A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Conclusion & alert: CVE-2024-12009 is rated Moderate Risk (48.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-20 | 0.18% | 0.32% | +0.14% |
| 2 | 2026-04-19 | 0.32% | 0.18% | -0.14% |
| 3 | 2026-01-14 | — | 0.32% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| zyxel | dx3300-t0_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:dx3300-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx3300-t1_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:dx3300-t1_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx3301-t0_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:dx3301-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx4510-b0_firmware | <= 5.17\(abyl.8\)c0 | cpe:2.3:o:zyxel:dx4510-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx4510-b1_firmware | <= 5.17\(abyl.8\)c0 | cpe:2.3:o:zyxel:dx4510-b1_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx5401-b0_firmware | <= 5.17\(abyo.6.4\)c0 | cpe:2.3:o:zyxel:dx5401-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | dx5401-b1_firmware | <= 5.17\(abyo.6.4\)c0 | cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:* |
| zyxel | ee6510-10_firmware | <= 5.19\(acjq.1\)c1 | cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3300-t0_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:ex3300-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3300-t1_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:ex3300-t1_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3301-t0_firmware | <= 5.50\(abvy.5.4\)c0 | cpe:2.3:o:zyxel:ex3301-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3500-t0_firmware | <= 5.44\(achr.3\)c0 | cpe:2.3:o:zyxel:ex3500-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3501-t0_firmware | <= 5.44\(achr.3\)c0 | cpe:2.3:o:zyxel:ex3501-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3510-b0_firmware | <= 5.17\(abup.13\)c0 | cpe:2.3:o:zyxel:ex3510-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3510-b1_firmware | <= 5.17\(abup.13\)c0 | cpe:2.3:o:zyxel:ex3510-b1_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex3600-t0_firmware | <= 5.70\(acif.0.5\)c0 | cpe:2.3:o:zyxel:ex3600-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5401-b0_firmware | <= 5.17\(abyo.6.4\)c0 | cpe:2.3:o:zyxel:ex5401-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5401-b1_firmware | <= 5.17\(abyo.6.4\)c0 | cpe:2.3:o:zyxel:ex5401-b1_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5501-b0_firmware | <= 5.17\(abry.5.3\)c0 | cpe:2.3:o:zyxel:ex5501-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5510-b0_firmware | <= 5.17\(abqx.10\)c0 | cpe:2.3:o:zyxel:ex5510-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5512-t0_firmware | <= 5.70\(aceg4.2\)c0 | cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5601-t0_firmware | <= 5.70\(acdz.3.6\)c0 | cpe:2.3:o:zyxel:ex5601-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex5601-t1_firmware | <= 5.70\(acdz.3.6\)c0 | cpe:2.3:o:zyxel:ex5601-t1_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex7501-b0_firmware | <= 5.18\(achn.1.3\)c0 | cpe:2.3:o:zyxel:ex7501-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ex7710-b0_firmware | <= 5.18\(acak.1.1\)c1 | cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | emg3525-t50b_firmware | <= 5.50\(abpm.9.3\)c0 | cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:* |
| zyxel | emg5523-t50b_firmware | <= 5.50\(abpm.9.3\)c0 | cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:* |
| zyxel | emg5723-t50k_firmware | <= 5.50\(abom.8.5\)c0 | cpe:2.3:o:zyxel:emg5723-t50k_firmware:*:*:*:*:*:*:*:* |
| zyxel | vmg3625-t50b_firmware | <= 5.50\(abpm.9.3\)c0 | cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:* |
| zyxel | vmg3927-t50k_firmware | <= 5.50\(abom.8.5\)c0 | cpe:2.3:o:zyxel:vmg3927-t50k_firmware:*:*:*:*:*:*:*:* |
| zyxel | vmg8623-t50b_firmware | <= 5.50\(abpm.9.3\)c0 | cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:* |
| zyxel | vmg8825-t50k_firmware | <= 5.50\(abom.8.5\)c0 | cpe:2.3:o:zyxel:vmg8825-t50k_firmware:*:*:*:*:*:*:*:* |
| zyxel | ax7501-b0_firmware | <= 5.17\(abpc.5.3\)c0 | cpe:2.3:o:zyxel:ax7501-b0_firmware:*:*:*:*:*:*:*:* |
| zyxel | ax7501-b1_firmware | <= 5.17\(abpc.5.3\)c0 | cpe:2.3:o:zyxel:ax7501-b1_firmware:*:*:*:*:*:*:*:* |
| zyxel | px3321-t1_firmware | <= 5.44\(acjb.1.1\)c0 | cpe:2.3:o:zyxel:px3321-t1_firmware:*:*:*:*:*:*:*:* |
| zyxel | px5301-t0_firmware | <= 5.44\(ackb.0.1\)c0 | cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | wx5600-t0_firmware | <= 5.70\(aceb.3.3\)c0 | cpe:2.3:o:zyxel:wx5600-t0_firmware:*:*:*:*:*:*:*:* |
| zyxel | wx5610-b0_firmware | <= 5.18\(acgj.0.1\)c0 | cpe:2.3:o:zyxel:wx5610-b0_firmware:*:*:*:*:*:*:*:* |