Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders
CVE: CVE-2026-6952
Summary
Zyxel has released patches for specific firmware versions of its DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders. These updates address the command injection vulnerability. Users are strongly advised to install the patches to ensure optimal protection.
What is the vulnerability?
CVE-2026-6952
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in certain firmware versions for DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. It is important to note that WAN access is disabled by default on these devices, and this attack can succeed only if user-configured passwords have been compromised.
What versions are vulnerable—and what should you do?
After a thorough investigation, we identified the affected products still within their vulnerability support period and released firmware patches to address the issue, as shown in the table below. Please note that the table does not include customized models specifically designed for ISP customers. Any product currently on the market that is not listed in the table is not affected.
| Product | Affected model | Affected version | Patch availability* |
|---|---|---|---|
| DSL/Ethernet CPE | DX3300-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| DX3300-T1 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 | |
| DX3301-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 | |
| DX4510-B0 | 5.17(ABYL.10.2)C0 and earlier | 5.17(ABYL.10.3)C0 | |
| DX4510-B1 | 5.17(ABYL.10.2)C0 and earlier | 5.17(ABYL.10.3)C0 | |
| DX5401-B1 | 5.17(ABYO.7.2)C0 and earlier | 5.17(ABYO.7.3)C0 | |
| EE3301-00 | 5.63(ACMU.3.1)C0 and earlier | 5.63(ACMU.3.2)C0 | |
| EE5301-00 | 5.63(ACLD.3.1)C0 and earlier | 5.63(ACLD.3.2)C0 | |
| EE6510-10 | 5.19(ACJQ.4.2)C0 and earlier | 5.19(ACJQ.4.3)C0 | |
| EMG3525-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 | |
| EMG5523-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 | |
| EX2210-T0 | 5.50(ACDI.2.5)C0 and earlier | 5.50(ACDI.2.6)C0 | |
| EX3300-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 | |
| EX3300-T1 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 | |
| EX3301-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 | |
| EX3500-T0 | 5.44(ACHR.5.1)C0 and earlier | 5.44(ACHR.6)C0 | |
| EX3501-T0 | 5.44(ACHR.5.1)C0 and earlier | 5.44(ACHR.6)C0 | |
| EX3600-T0 | 5.70(ACIF.2.1)C0 and earlier | 5.70(ACIF.3.1)C0 | |
| EX5512-T0 | 5.70(ACEG.5.6)C0 and earlier | 5.70(ACEG.5.7)C0 | |
| EX5401-B1 | 5.17(ABYO.7.2)C0 and earlier | 5.17(ABYO.7.3)C0 | |
| EX5601-T0 | 5.70(ACDZ.6)C0 and earlier | 5.70(ACDZ.6.1)C0 | |
| EX5601-T1 | 5.70(ACDZ.6)C0 and earlier | 5.70(ACDZ.6.1)C0 | |
| EX7501-B0 | 5.18(ACHN.3.2)C0 and earlier | 5.18(ACHN.3.3)C0 | |
| EX7710-B0 | 5.18(ACAK.1.7)C0 and earlier | 5.18(ACAK.1.8)C0 | |
| GM4100-B0 | 5.18(ACCL.2.1)C0 and earlier | 5.18(ACCL.2.2)C0 | |
| VMG3625-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 | |
| VMG4005-B50A | 5.17(ABQA.3.3)C0 and earlier | 5.17(ABQA.3.4)C0 | |
| VMG4005-B60A | 5.17(ABQA.3.3)C0 and earlier | 5.17(ABQA.3.4)C0 | |
| VMG8623-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 | |
| Fiber ONTs | AM7510-00 | 5.63(ACOR.0.2)C0 and earlier | 5.63(ACOR.0.3)C0 |
| AX7501-B1 | 5.17(ABPC.7.2)C0 and earlier | 5.17(ABPC.8)C0 | |
| PE3301-00 | 5.63(ACMT.3.1)C0 and earlier | 5.63(ACMT.3.2)C0 | |
| PE5301-01 | 5.63(ACOJ.3.1)C0 and earlier | 5.63(ACOJ.3.2)C0 | |
| PM3100-T0 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 | |
| PM5100-T0 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 | |
| PM5100-T1 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 | |
| PM7300-T0 | 5.42(ABYY.4.1)C0 and earlier | 5.42(ABYY.4.2)C0 | |
| PM7500-00 | 5.61(ACKK.1.4)C0 and earlier | 5.61(ACKK.1.5)C0 | |
| PX5301-T0 | 5.44(ACKB.0.7)C0 and earlier | 5.44(ACKB.0.8)C0 | |
| Wireless Extenders | WE3300-00 | 5.70(ACKA.2)C0 and earlier | 5.70(ACKA.2.1)C0 |
| WX3100-T0 | 5.50(ABVL.5)C0 and earlier | 5.50(ABVL.5.1)C0 | |
| WX5600-T0 | 5.70(ACEB.6)C0 and earlier | 5.70(ACEB.6.2)C0 |
* Please contact your Zyxel sales representative or support team to obtain the file.
For ISPs, please contact your Zyxel sales or service representatives for further details.
For end-users who acquired their Zyxel device from an ISP, we recommend reaching out directly to the ISP's support team, as the device may have custom-built settings.
For end-users who purchased their Zyxel device themselves, please contact your local Zyxel support team for the new firmware file to ensure optimal protection, or visit Zyxel's Community for further assistance.
Got a question?
Please contact your local service rep or visit Zyxel's Community for further information or assistance.
Acknowledgment
Thanks to William Honnér for reporting the issue to us.
Revision history
2026-7-21: Initial release