CVE-2024-12009: OS Command Injection
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12009?
CVE-2024-12009 is a high-severity post-authentication command injection vulnerability.
How do I fix CVE-2024-12009?
To fix CVE-2024-12009, upgrade the Zyxel EX5601-T1 firmware to a version later than V5.70(ACDZ.3.6)C0.
Who is affected by CVE-2024-12009?
CVE-2024-12009 affects users of Zyxel EX5601-T1 firmware versions V5.70(ACDZ.3.6)C0 and earlier.
What type of vulnerability is CVE-2024-12009?
CVE-2024-12009 is a command injection vulnerability that allows an attacker to execute OS commands.
What permissions are required to exploit CVE-2024-12009?
Exploiting CVE-2024-12009 requires authenticated administrator privileges on the device.