First published: Tue Mar 11 2025(Updated: )
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel EX5601-T1 Firmware | <=V5.70(ACDZ.3.6)C0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12009 is a high-severity post-authentication command injection vulnerability.
To fix CVE-2024-12009, upgrade the Zyxel EX5601-T1 firmware to a version later than V5.70(ACDZ.3.6)C0.
CVE-2024-12009 affects users of Zyxel EX5601-T1 firmware versions V5.70(ACDZ.3.6)C0 and earlier.
CVE-2024-12009 is a command injection vulnerability that allows an attacker to execute OS commands.
Exploiting CVE-2024-12009 requires authenticated administrator privileges on the device.