Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders
CVE: CVE-2026-6952
Summary
Zyxel has released patches for specific firmware versions of its DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders. These updates address the command injection vulnerability. Users are strongly advised to install the patches to ensure optimal protection.
What is the vulnerability?
CVE-2026-6952
A post-authentication command injection vulnerability in the “LogServer” field of the syslog component in certain firmware versions for DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. It is important to note that WAN access is disabled by default on these devices, and this attack can succeed only if user-configured passwords have been compromised.
What versions are vulnerable—and what should you do?
After a thorough investigation, we identified the affected products still within their vulnerability support period and released firmware patches to address the issue, as shown in the table below. Please note that the table does not include customized models specifically designed for ISP customers. Any product currently on the market that is not listed in the table is not affected.
| Affected model | Affected version | Patch availability* |
|---|---|---|
| DSL/Ethernet CPE | ||
| DX3300-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| DX3300-T1 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| DX3301-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| DX4510-B0 | 5.17(ABYL.10.2)C0 and earlier | 5.17(ABYL.10.3)C0 |
| DX4510-B1 | 5.17(ABYL.10.2)C0 and earlier | 5.17(ABYL.10.3)C0 |
| DX5401-B1 | 5.17(ABYO.7.2)C0 and earlier | 5.17(ABYO.7.3)C0 |
| EE3301-00 | 5.63(ACMU.3.1)C0 and earlier | 5.63(ACMU.3.2)C0 |
| EE5301-00 | 5.63(ACLD.3.1)C0 and earlier | 5.63(ACLD.3.2)C0 |
| EE6510-10 | 5.19(ACJQ.4.2)C0 and earlier | 5.19(ACJQ.4.3)C0 |
| EMG3525-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 |
| EMG5523-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 |
| EX2210-T0 | 5.50(ACDI.2.5)C0 and earlier | 5.50(ACDI.2.6)C0 |
| EX3300-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| EX3300-T1 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| EX3301-T0 | 5.50(ABVY.8)C0 and earlier | 5.50(ABVY.8.1)C0 |
| EX3500-T0 | 5.44(ACHR.5.1)C0 and earlier | 5.44(ACHR.6)C0 |
| EX3501-T0 | 5.44(ACHR.5.1)C0 and earlier | 5.44(ACHR.6)C0 |
| EX3600-T0 | 5.70(ACIF.2.1)C0 and earlier | 5.70(ACIF.3.1)C0 |
| EX5512-T0 | 5.70(ACEG.5.6)C0 and earlier | 5.70(ACEG.5.7)C0 |
| EX5401-B1 | 5.17(ABYO.7.2)C0 and earlier | 5.17(ABYO.7.3)C0 |
| EX5601-T0 | 5.70(ACDZ.6)C0 and earlier | 5.70(ACDZ.6.1)C0 |
| EX5601-T1 | 5.70(ACDZ.6)C0 and earlier | 5.70(ACDZ.6.1)C0 |
| EX7501-B0 | 5.18(ACHN.3.2)C0 and earlier | 5.18(ACHN.3.3)C0 |
| EX7710-B0 | 5.18(ACAK.1.7)C0 and earlier | 5.18(ACAK.1.8)C0 |
| GM4100-B0 | 5.18(ACCL.2.1)C0 and earlier | 5.18(ACCL.2.2)C0 |
| VMG3625-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 |
| VMG4005-B50A | 5.17(ABQA.3.3)C0 and earlier | 5.17(ABQA.3.4)C0 |
| VMG4005-B60A | 5.17(ABQA.3.3)C0 and earlier | 5.17(ABQA.3.4)C0 |
| VMG8623-T50B | 5.50(ABPM.9.8)C0 and earlier | 5.50(ABPM.9.9)C0 |
| Fiber ONTs | ||
| AM7510-00 | 5.63(ACOR.0.2)C0 and earlier | 5.63(ACOR.0.3)C0 |
| AX7501-B1 | 5.17(ABPC.7.2)C0 and earlier | 5.17(ABPC.8)C0 |
| PE3301-00 | 5.63(ACMT.3.1)C0 and earlier | 5.63(ACMT.3.2)C0 |
| PE5301-01 | 5.63(ACOJ.3.1)C0 and earlier | 5.63(ACOJ.3.2)C0 |
| PM3100-T0 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 |
| PM5100-T0 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 |
| PM5100-T1 | 5.42(ACBF.4.3)C0 and earlier | 5.42(ACBF.4.4)C0 |
| PM7300-T0 | 5.42(ABYY.4.1)C0 and earlier | 5.42(ABYY.4.2)C0 |
| PM7500-00 | 5.61(ACKK.1.4)C0 and earlier | 5.61(ACKK.1.5)C0 |
| PX5301-T0 | 5.44(ACKB.0.7)C0 and earlier | 5.44(ACKB.0.8)C0 |
| Wireless Extenders | ||
| WE3300-00 | 5.70(ACKA.2)C0 and earlier | 5.70(ACKA.2.1)C0 |
| WX3100-T0 | 5.50(ABVL.5)C0 and earlier | 5.50(ABVL.5.1)C0 |
| WX5600-T0 | 5.70(ACEB.6)C0 and earlier | 5.70(ACEB.6.2)C0 |
Got a question?
For our ISP customers, please contact your Zyxel sales or service representatives for more information. For customers who have acquired Zyxel devices through an ISP, please directly contact your ISP's support team, as the devices may have custom configurations.
Acknowledgment
Thanks to William Honnér for reporting the issue to us.
Revision history
2026-07-21: Initial release