Full Report
Zyxel security advisory (AV26-725)
Analysis Summary
# Vulnerability: Post-Authentication Command Injection in Multiple Zyxel Devices
## CVE Details
- **CVE ID:** CVE-2024-5412
- **CVSS Score:** 7.2 (High)
- **CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
## Affected Systems
- **Products:** DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders.
- **Versions:**
- **DSL/Ethernet CPE:** AM3100-B0, EX3300-T0, EX3301-T0, EX5601-T0, and others (refer to vendor advisory for full model list).
- **Fiber ONTs:** PM3100-G0, PM5100-G0, PM7100-G0.
- **Wireless Extenders:** WX3100-T0, WX3401-B0, WX5600-T0.
- **Configurations:** Systems running firmware versions prior to the July 2026 release.
## Vulnerability Description
A command injection vulnerability exists in the web management interface of specific Zyxel DSL/Ethernet CPE, Fiber ONT, and WiFi extender devices. The flaw allows an authenticated attacker with administrative privileges to execute arbitrary OS commands on the affected device by sending a specially crafted HTTP request. This occurs due to improper validation of user-supplied input before it is passed to a system shell.
## Exploitation
- **Status:** Not reported as exploited in the wild at the time of advisory; No public PoC currently identified.
- **Complexity:** Low (Requires valid credentials).
- **Attack Vector:** Network (Typically via the local management interface).
## Impact
- **Confidentiality:** High (Total access to system data).
- **Integrity:** High (Ability to modify system configurations and firmware).
- **Availability:** High (Ability to crash the device or render it inoperable).
## Remediation
### Patches
Zyxel has released firmware updates for the affected models. Users are advised to install the latest available firmware via the device management interface or the Zyxel support portal.
- **Firmware Version:** Varies by model (Refer to the specific version string listed in the Zyxel Security Advisory table).
### Workarounds
- **Restrict Management Access:** Disable remote management (WAN-side access) and restrict local management access to trusted IP addresses only.
- **Change Default Credentials:** Ensure all administrative accounts have strong, unique passwords to prevent unauthorized access to the management interface.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative logins, unexpected reboots, or unauthorized changes to DNS and routing settings.
- **Detection Methods:** Audit web server logs for suspicious characters (e.g., `;`, `|`, `&`, `$()`) within HTTP POST requests directed at the management UI.
## References
- **Zyxel Advisory:** hxxps[://]www[.]zyxel[.]com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026
- **Zyxel Security Center:** hxxps[://]www[.]zyxel[.]com/global/en/support/security-advisories
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/zyxel-security-advisory-av26-725