cbcvebase.
CVE-2024-12009
published 2025-03-11

CVE-2024-12009: A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelax7501-b0_firmware<= 5.17\(abpc.5.3\)c0
zyxelax7501-b1_firmware<= 5.17\(abpc.5.3\)c0
zyxeldx3300-t0_firmware<= 5.50\(abvy.5.4\)c0
zyxeldx3300-t1_firmware<= 5.50\(abvy.5.4\)c0
zyxeldx3301-t0_firmware<= 5.50\(abvy.5.4\)c0
zyxeldx4510-b0_firmware<= 5.17\(abyl.8\)c0
zyxeldx4510-b1_firmware<= 5.17\(abyl.8\)c0
zyxeldx5401-b0_firmware<= 5.17\(abyo.6.4\)c0
zyxeldx5401-b1_firmware<= 5.17\(abyo.6.4\)c0
zyxelee6510-10_firmware<= 5.19\(acjq.1\)c1
zyxelemg3525-t50b_firmware<= 5.50\(abpm.9.3\)c0
zyxelemg5523-t50b_firmware<= 5.50\(abpm.9.3\)c0
zyxelemg5723-t50k_firmware<= 5.50\(abom.8.5\)c0
zyxelex3300-t0_firmware<= 5.50\(abvy.5.4\)c0
zyxelex3300-t1_firmware<= 5.50\(abvy.5.4\)c0
zyxelex3301-t0_firmware<= 5.50\(abvy.5.4\)c0
zyxelex3500-t0_firmware<= 5.44\(achr.3\)c0
zyxelex3501-t0_firmware<= 5.44\(achr.3\)c0
zyxelex3510-b0_firmware<= 5.17\(abup.13\)c0
zyxelex3510-b1_firmware<= 5.17\(abup.13\)c0
zyxelex3600-t0_firmware<= 5.70\(acif.0.5\)c0
zyxelex5401-b0_firmware<= 5.17\(abyo.6.4\)c0
zyxelex5401-b1_firmware<= 5.17\(abyo.6.4\)c0
zyxelex5501-b0_firmware<= 5.17\(abry.5.3\)c0
zyxelex5510-b0_firmware<= 5.17\(abqx.10\)c0