Zyxel AX7501 with XGSPON SFP+, VLAN 10

Zyxel AX7501 with XGSPON SFP+, VLAN 10


Product rating for Zyxel AX7501 with XGSPON SFP+, VLAN 10

avatar
TingedPolmat49

4 years ago

A security nightmare: DO NOT BUY - DO NOT USE

Getting a new firmware is difficult if not impossible

https://www.opencve.io/cve

Zyxel portal is a nightmare, AX7501-B0 return ZERO results
try https://www.zyxel.com/support...


Asked in official forums:
"For the new firmware, it may depends on your supplier.
If your AX7501-B0 comes from ISP, you may need to check with your ISP for new firmware version."

Found a security advisory by PURE luck in google, yes I have the wrong one V5.15(ABPC.0)C0 (default)
https://support.zyxel.eu/hc...
And again NO EASY way to get access to the firmware.

Would have been acceptable in year 2000, not any more in 2022. Having 10GB is not worth the security risk.

Huge Firmware mess:
Your ISP customize the image (why, how, where is the protocol) so
* you buy at digitec or elsewhere -> you can contact xyzel and hope they will help you
* you got the router from swisscom, salt, and co -> you have to use another customized firmware from your provider -> security wise a nightmare as well
* you got the router from init7 -> youre lucky you can apply C0 (aka default Zyxel firmware)

Getting new firmware (all are OUTDATED)
Swisscom: ftp://zyxel@ftp.zyxel.ch/AX7501-B0/OBM/V517ABPC1C0.bin
Init7: https://nextcloud.init7.net/s... (Passwort: ANbrM7BLG5)

2023.4
Latest firmware V517ABPC3D0 solved some issues but behind the scene still contains
* Samba daemon 3.6.25 End of life since 2015
* Linux kernel 4.1.52 end of life 2018
* OpenSSL 1.1.1 is EOL in sept 2023, will they update before?
and a LOT more outdated software
* Will never run OpenWrt, it use Broadcom see https://forum.openwrt.org/t... but run in fact behind the scene a butchered OpenWrt 14.03 with magical Broadcom binaries.
* Mac mini has issues with 5GHz, Apple TV 4K is also struggling. Use only 2.4GHz but will dump router & go back to 1gb
 

Pro

  • none

Contra

  • a challenge to update firmware: ISP also modify firmware
  • no firmware auto update or alerts
  • interface is difficult to use (even after 21 years in IT)
  • Instable wifi 5GHz
  • Zyxel should not be allowed to sell any network devices
  • SBOM of Xyzel not public. The State of Software Bill of Materials show lot of packages outdated....
  • ZYXEL don't take security seriously
  • firmware: no SHASUM, untrusted FTP, images not signed
  • Can not switch off status led
  • Magical binary to update??
  • you can ask ZYXEL for the firmware source code, no response
  • use butchered OpenWrt version 14.03 not 22.03
  • avatar
    TingedPolmat49

    4 years ago

    something better like what?

    This router will be front facing and resolve DNS queries and if it get easily infected or start DDOS attacks...

    bad luck, OpenWRT can not be installed on it....

  • avatar
    10GigabitPeter

    4 years ago

    Damn. how do i get the update as a sunrise user?

  • avatar
    PlatterOhmeo79

    3 years ago

    while I agree with the OP, at least init7 seems to update it's customers' firmware over the wire. I don't know if all providers do this, though.

  • avatar
    Winterfalke

    3 years ago

    I contacted Init7 and asked for a firmware update. They sent me the file.
    But it's a hassle to ask them for an update and you don't even know what's in it or when there will be another update.
    In the meantime I switched to
    an AX89X, which is now not only better but also cheaper. 

  • avatar
    JiSiN

    3 years ago

    @Winterfalke
    Is this V517ABPC1b5.zip (for P2P)?

  • avatar
    10GigabitPeter

    3 years ago

    Here is the latest firmware:'
    V517ABPC21D0.zip

    ftp(PUNKT)zyxel.ch zyxel and zyxel as username and password.

    The free box without branding from Sunrise can be updated and runs very well with the latest firmware.

  • avatar
    JiSiN

    3 years ago

    If I am not mistaken, "V517ABPC21D0.zip" is for XGS-PON (P2MP).
    "V517ABPC1b5.zip" would be for e.g. Fiber7-X (P2P)

  • avatar
    JiSiN

    3 years ago

    @Winterfalcon
    What else would interest me...
    How much do you get WAN <--> LAN throughput on the AX89X?
    Does it more or less reach the 10Gbps?

    Was going to pull the AX89X about 1 year ago, but I wasn't quite convinced yet.
    I
    have been using Asus routers with the Merlin FW for many years.
    Currently I am waiting for RT-BE96U & GT-BE98.
    Then hopefully it will be time for Fiber7-X.

    Unfortunately I can't find anything useful in HW for Fiber7-X2.
    Since I want to run it in the living room and not in a server rack lol
     

  • avatar
    Winterfalke

    3 years ago

    @JiSiN
    The last request I sent to Init7 was in July and they sent me a dropbox link which is no longer valid. The firmware file was AX7501-B0_Firmware_5.15%28ABPC.0%29C0.zip so that corresponds to V5.15(ABPC.0)C0 so an older
    version.
    Regarding your second question: unfortunately I cannot test 10G at the moment.
    From past experience, there is no application area I use that reaches 4Gigabit. Not because the line is slow, but because the servers on the opposite side don't provide enough bandwidth (example Steam downloads was my record under just under 4Gigabit, mostly rather lower).
    So for practical reasons I use a 2.5G connection from my mainboard, which is more than sufficient for my purposes.
    One of the reasons why I didn't go for Fiber-X2 from the beginning is that 10G is already absolutely overkill and I didn't expect any online server to support that when I download something.
     

  • avatar
    10GigabitPeter

    3 years ago

    @Winterfalke: with V517ABPC21D0.zip the zyxel works fine. Your version was older. I had problems with the 10gb port before (see changelog).

  • avatar
    dokterdok

    3 years ago

    V517ABPC21D0.zip works fine with init7, I tried it. A newer V5.17(ABPC.3)C0 was apparently released which is supposed to patch security vulnerabilities. See https://www.zyxel.com/global...

    I
    haven't found download links. I agree with OP that offering no public way to download the latest security fixes is just insane. 

  • avatar
    TingedPolmat49

    3 years ago

    Nightmare continue....

    If you're on V5.17(ABPC.1)C0. this is insecure since

    CVE-2022-45440 1 Zyxel 2 Ax7501-b0, Ax7501-b0 Firmware 2023-01-25 N/A 4.4 MEDIUM
    A vulnerability exists in the FTP server of the Zyxel AX7501-B0
    firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability to access the root file system by creating a symbolic link on external storage media, such as a USB flash drive, and then logging into the FTP server on a vulnerable device.
    CVE-2022-45439 1 Zyxel 2 Ax7501-b0, Ax7501-b0 Firmware 2023-01-24 N/A 6.5 MEDIUM
    A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the device by leveraging another known vulnerability.
    CVE-2022-43392 1 Zyxel 96 Ax7501-b0, Ax7501-b0 Firmware, Dx3301-t0 and 93 more 2023-01-18 N/A 6.5 MEDIUM
    A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.

    Zyxel has a solution, update to V5.17(ABPC.3)C0 but damn IT IS IMPOSSIBLE TO LOCATE IT
    https://community.zyxel.com/en...

    All known vulnerabilities so far (known but there is more for sure)
    https://www.opencve.io/cve

    I am more and more thinking about selling this device and go back to 1GB/s bandwidth, using openWRT.

    These companies should go out of business
     

  • avatar
    dokterdok

    3 years ago

    I ended up contacting support@init7.net, they sent me a link to V5.17(ABPC.3)b2 , a beta version dated Oct 20 2022.
    Not clear if it solves the vulnerabilities mentioned above. The release notes do mention this fix: "[#176288]Zyxel-SI-1433
    [Vulnerability] Buffer overflow vulnerabilities and command injection vulnerability for AX7501-B1 Generic" 

  • avatar
    10GigabitPeter

    3 years ago

    Version V5.17(ABPC.3)D0 is now available:

    Bug Fixed
    Security
    [#178839]
    178839][Security]Zyxel SI 1441 [Vulnerability] Hidden SSID and
    symbolic Links in ftpd of AX7501 B0

  • avatar
    richi207

    2 years ago

    Is the V5.17(ABPC.3)D0 for the AX7501-b0? According to the FTP, it is for the AX7501-b1, or did I look at it wrong?

  • avatar
    dokterdok

    2 years ago

    V5.17(ABPC.4)C0 is out, which includes a number of security vulnerabilities fixes, including a "Possible security flaw that allows to retrieve root password". Reminder to all owners to regularly contact your ISP and request the latest firmware. Zyxel CH's own FTP is outdated, no point looking there.
    What a circus :D
     

  • avatar
    dokterdok

    2 years ago

    I just received it today. Init7 sent me a password protected link and instructions. Haven’t flashed it yet.

  • avatar
    dokterdok

    2 years ago

    Security fixes included in V5.17(ABPC.4)C0, from the release notes:
    * [#190137][#230500907] Possible security flaw that allows to
    retrieve root password.
    * [#184254][CVE-2022-4203,4304,4450][CVE-2023-0215~0217,0286,0
    401][Zyxel-SI-1464]
    [Vulnerability] OpenSSL multiple vulnerabilities
    * [#182244][ETSI EN 303 645] The consumer IoT device shall protect
    the confidentiality of critical security parameters that are
    communicated via remotely accessible network interfaces.
    * [#182251][ETSI EN 303 645] 5.8-2: The confidentiality of sensitive
    personal data communicated between the device and
    associated services shall be protected, with cryptography
    appropriate to the properties of the technology and usage.
     

  • avatar
    10GigabitPeter

    2 years ago

    I contacted my isp green.ch and they sent me the version V513ABQO1b4_D0.bin it without any release notes. I just asked them for more informations. This version is outdated? V513 must be very old, right? I am confused since I cannot find any changelog 

  • avatar
    dokterdok

    2 years ago

    Looking at Zyxel's ftp, it sounds like they sent you a firmware for a different model, the Zyxel XMG3927. And that firmware you mentioned dates back to 2021.

  • avatar
    10GigabitPeter

    2 years ago

    Thank you. I just wrote green to inform them. Hopefully the manage to send me the correct version. It's a pity that the firmware is not available publicly

  • avatar
    10GigabitPeter

    2 years ago

    Hi dokterdok

    Now i received the following version, D0 and not C0 (V5.17(ABPC.4)C0). Is this already a newer one? (V517ABPC4D0.bin), release notes are still missing. I just asked them to send them to me as well. Here is a
    google drive link drive(dot)google(dot)com/file/d/1WbbmmWYsbHmn8QQD0Y1v9cvq2eSQzNkB/view?usp=sharing

    I will try to flash this evening.
     

  • avatar
    10GigabitPeter

    2 years ago

    ahh i got the AX7501-B1 and not the AX7501-B0, maybe thats why i got the V517ABPC4D0.bin

  • avatar
    dokterdok

    2 years ago

    C0, D0 etc. seem to be linked to ISP-specific firmware configurations, which is why it's best to stick to what your ISP recommends.
    I've moved on to the TP-Link BE85 a while ago and now only use this Zyxel router as a backup.

  • avatar
    dokterdok

    1 year ago

    @Hillmann111
    Those firmwares you linked to above are insecure and date back a couple of years.
    The latest one is V5.17(ABPC.5)C0, released in late April 2024. It should be available if you ask your ISP. It includes a less
    ancient OpenSSL release (3.1.2) and security vulnerabilities fixes. 

  • avatar
    MüderPuzzlo87

    1 year ago

    iway.ch (Swiss ISP) currently publishes the D0 firmware for this router here:

    https://firmware.iway.ch/zyxel...

    The following version is currently available:

    V5.17(ABPC.5.3)D0 (Release date: 04.10.2024)

    This firmware
    is also compatible with Init7 (I have tested it)