CVE-2024-12010: OS Command Injection
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12010?
CVE-2024-12010 has been rated as a high severity vulnerability due to its potential for allowing authenticated attackers to execute OS commands.
How do I fix CVE-2024-12010?
To remediate CVE-2024-12010, it is recommended to upgrade the firmware of the Zyxel AX7501-B1 to a version higher than V5.17(ABPC.5.3)C0.
Who is affected by CVE-2024-12010?
CVE-2024-12010 affects devices running Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier.
What type of vulnerability is CVE-2024-12010?
CVE-2024-12010 is a post-authentication command injection vulnerability.
What can an attacker do with CVE-2024-12010?
An attacker exploiting CVE-2024-12010 can execute arbitrary operating system commands on the vulnerable Zyxel devices.