7.2
HIGH CVSS 3.1
CVE-2024-12010
Zyxel AX7501-B1 Command Injection Vulnerability
Description

A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.

INFO

Published Date :

March 11, 2025, 2:15 a.m.

Last Modified :

Jan. 13, 2026, 4:19 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2024-12010 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Zyxel dx3301-t0_firmware
2 Zyxel dx4510-b1_firmware
3 Zyxel dx5401-b0_firmware
4 Zyxel emg3525-t50b_firmware
5 Zyxel emg5523-t50b_firmware
6 Zyxel emg5723-t50k_firmware
7 Zyxel ex3301-t0_firmware
8 Zyxel ex3510-b0_firmware
9 Zyxel ex5401-b0_firmware
10 Zyxel ex5501-b0_firmware
11 Zyxel ex5510-b0_firmware
12 Zyxel ex5512-t0_firmware
13 Zyxel ex5601-t0_firmware
14 Zyxel ex5601-t1_firmware
15 Zyxel vmg3927-t50k_firmware
16 Zyxel vmg8623-t50b_firmware
17 Zyxel vmg8825-t50k_firmware
18 Zyxel ax7501-b0_firmware
19 Zyxel wx3100-t0_firmware
20 Zyxel wx3401-b0_firmware
21 Zyxel wx5600-t0_firmware
22 Zyxel vmg3625-t50b_firmware
23 Zyxel wx5600-t0
24 Zyxel wx3401-b0
25 Zyxel wx3100-t0
26 Zyxel px3321-t1_firmware
27 Zyxel px3321-t1
28 Zyxel ax7501-b1_firmware
29 Zyxel ax7501-b1
30 Zyxel ax7501-b0
31 Zyxel vmg8825-t50k
32 Zyxel vmg8623-t50b
33 Zyxel vmg3927-t50k
34 Zyxel vmg3625-t50b
35 Zyxel emg5723-t50k
36 Zyxel emg5523-t50b
37 Zyxel emg3525-t50b
38 Zyxel ex7710-b0_firmware
39 Zyxel ex7710-b0
40 Zyxel ex7501-b0_firmware
41 Zyxel ex7501-b0
42 Zyxel ex5601-t1
43 Zyxel ex5601-t0
44 Zyxel ex5512-t0
45 Zyxel ex5510-b0
46 Zyxel ex5401-b1_firmware
47 Zyxel ex5401-b1
48 Zyxel ex5401-b0
49 Zyxel ex3510-b0
50 Zyxel ex3501-t0_firmware
51 Zyxel ex3501-t0
52 Zyxel ex3500-t0_firmware
53 Zyxel ex3500-t0
54 Zyxel ex3301-t0
55 Zyxel ex3300-t1_firmware
56 Zyxel ex3300-t1
57 Zyxel ex3300-t0_firmware
58 Zyxel ex3300-t0
59 Zyxel dx5401-b1_firmware
60 Zyxel dx5401-b1
61 Zyxel dx5401-b0
62 Zyxel dx4510-b0_firmware
63 Zyxel dx4510-b0
64 Zyxel dx3301-t0
65 Zyxel dx3300-t1_firmware
66 Zyxel dx3300-t1
67 Zyxel dx3300-t0_firmware
68 Zyxel dx3300-t0
69 Zyxel ex3600-t0_firmware
70 Zyxel ex3600-t0
71 Zyxel ex3510-b1_firmware
72 Zyxel ex3510-b1
73 Zyxel dx4510-b1
74 Zyxel ex5501-b0
75 Zyxel ee6510-10_firmware
76 Zyxel ee6510-10
77 Zyxel px5301-t0_firmware
78 Zyxel px5301-t0
79 Zyxel wx3401-b1_firmware
80 Zyxel wx3401-b1
81 Zyxel wx5610-b0_firmware
82 Zyxel wx5610-b0
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH [email protected]
Solution
Update firmware to fix post-authentication command injection vulnerability.
  • Update Zyxel firmware to the latest version.
  • Apply vendor patches for security vulnerabilities.
  • Restrict administrator privileges to authorized users.
Public PoC/Exploit Available at Github

CVE-2024-12010 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-12010.

URL Resource
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerabilities-in-certain-dsl-ethernet-cpe-fiber-ont-and-wifi-extender-devices-03-11-2025 Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-12010 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Security Research Collection

Updated: 2 months, 1 week ago
0 stars 0 fork 0 watcher
Born at : Nov. 5, 2025, 5:42 a.m. This repo has been linked 8 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-12010 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2024-12010 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jan. 13, 2026

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.18(acgj.0.1)c0 OR cpe:2.3:h:zyxel:wx5610-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx3300-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:dx3300-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx3300-t1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:dx3300-t1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx3301-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:dx3301-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyl.8)c0 OR cpe:2.3:h:zyxel:dx4510-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyl.8)c0 OR cpe:2.3:h:zyxel:dx4510-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx5401-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyo.6.4)c0 OR cpe:2.3:h:zyxel:dx5401-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyo.6.4)c0 OR cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.19(acjq.1)c1 OR cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3300-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:ex3300-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3300-t1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:ex3300-t1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3301-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvy.5.4)c0 OR cpe:2.3:h:zyxel:ex3301-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3500-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.44(achr.3)c0 OR cpe:2.3:h:zyxel:ex3500-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3501-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.44(achr.3)c0 OR cpe:2.3:h:zyxel:ex3501-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abup.13)c0 OR cpe:2.3:h:zyxel:ex3510-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abup.13)c0 OR cpe:2.3:h:zyxel:ex3510-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex3600-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.70(acif.0.5)c0 OR cpe:2.3:h:zyxel:ex3600-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5401-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyo.6.4)c0 OR cpe:2.3:h:zyxel:ex5401-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5401-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abyo.6.4)c0 OR cpe:2.3:h:zyxel:ex5401-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5501-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abry.5.3)c0 OR cpe:2.3:h:zyxel:ex5501-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abqx.10)c0 OR cpe:2.3:h:zyxel:ex5510-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.70(aceg4.2)c0 OR cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5601-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.70(acdz.3.6)c0 OR cpe:2.3:h:zyxel:ex5601-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex5601-t1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.70(acdz.3.6)c0 OR cpe:2.3:h:zyxel:ex5601-t1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex7501-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.18(achn.1.3)c0 OR cpe:2.3:h:zyxel:ex7501-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.18(acak.1.1)c1 OR cpe:2.3:h:zyxel:ex7710-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abpm.9.3)c0 OR cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abpm.9.3)c0 OR cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:emg5723-t50k_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abom.8.5)c0 OR cpe:2.3:h:zyxel:emg5723-t50k:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abpm.9.3)c0 OR cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:vmg3927-t50k_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abom.8.5)c0 OR cpe:2.3:h:zyxel:vmg3927-t50k:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abpm.9.3)c0 OR cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:vmg8825-t50k_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abom.8.5)c0 OR cpe:2.3:h:zyxel:vmg8825-t50k:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ax7501-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abpc.5.3)c0 OR cpe:2.3:h:zyxel:ax7501-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:ax7501-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abpc.5.3)c0 OR cpe:2.3:h:zyxel:ax7501-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.44(acjb.1.1)c0 OR cpe:2.3:h:zyxel:px3321-t1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.44(achk.0.3)c0 OR cpe:2.3:h:zyxel:px3321-t1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.44(ackb.0.1)c0 OR cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:wx3100-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.50(abvl.4.5)c0 OR cpe:2.3:h:zyxel:wx3100-t0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:wx3401-b0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abve.2.6)c0 OR cpe:2.3:h:zyxel:wx3401-b0:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:wx3401-b1_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.17(abve.2.6)c0 OR cpe:2.3:h:zyxel:wx3401-b1:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:zyxel:wx5600-t0_firmware:*:*:*:*:*:*:*:* versions up to (including) 5.70(aceb.3.3)c0 OR cpe:2.3:h:zyxel:wx5600-t0:-:*:*:*:*:*:*:*
    Added Reference Type Zyxel Corporation: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerabilities-in-certain-dsl-ethernet-cpe-fiber-ont-and-wifi-extender-devices-03-11-2025 Types: Vendor Advisory
  • New CVE Received by [email protected]

    Mar. 11, 2025

    Action Type Old Value New Value
    Added Description A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-78
    Added Reference https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerabilities-in-certain-dsl-ethernet-cpe-fiber-ont-and-wifi-extender-devices-03-11-2025
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.2
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact