The worst router and brand Zyxel AX7501-B0 I've seen in 35 years @ Cédric Walter | Monday, Jan 8, 2024 | 4 minutes read | 772 Words | Update at Tuesday, Feb 27, 2024

Zyxel is a company known for producing networking equipment, including routers, switches, and other network infrastructure devices.

Security Warning: Avoid Purchasing and Using This Device

List of known vulnerabilities https://www.opencve.io/cve?vendor=zyxel&product=ax7501-b0_firmware

Obtaining updated firmware proves challenging, if not impossible

Zyxel portal is a nightmare, AX7501-B0 return ZERO results try https://www.zyxel.com/support/download_landing.shtml

Official forums indicate firmware availability depends on the supplier, urging users to consult their ISP for AX7501-B0 updates.

A security advisory discovered via Google highlights firmware version V5.15(ABPC.0)C0 as outdated, with no straightforward means to access the latest firmware.

This situation would have been acceptable in 2000, but in 2022, it’s unacceptable. The 10GB speed isn’t worth compromising security.

Firmware updates? good luck getting one

  • ISPs customize images, leading to varied support experiences.
  • Purchased from a retailer? Contact Zyxel for potential assistance.
  • Provided by Swisscom, Salt, etc.? Customized firmware from your provider poses security risks.
  • Acquired from Init7? Applying C0 (default Zyxel firmware) is a fortunate option.

Obtaining new firmware remains challenging, with outdated versions for Swisscom and Init7, each with its unique hurdles.

The latest firmware, V517ABPC3D0 (2023.4), addresses some issues but contains outdated software elements, including the Samba daemon, Linux kernel, and OpenSSL.

Broadcom chipset FOSS support is shit

Despite claims of Broadcom compatibility, the device doesn’t run really OpenWrt smoothly and relies on a modified OpenWrt 14.03 version (OpenWrt older than October 2014!) with butchered and magical Broadcom binaries. see https://forum.openwrt.org/t/zyxel-ax7501-with-xgspon-sfp-10gb-fiber-router-support/157738 Source code can be obtained but code is so old, has broadcom binary, that there is no easy migration path to 23.x

Zyxel Official forums answers:

“For the new firmware, it may depends on your supplier. If your AX7501-B0 comes from ISP, you may need to check with your ISP for new firmware version.”

Found a security advisory by PURE luck in google, yes I have the wrong one V5.15(ABPC.0)C0 (default) support.zyxel.eu/hc/en-us/articles/360019108619-Zyxel-securi… And again NO EASY way to get access to the firmware.

Would have been acceptable in year 2000, not any more in 2022. Having 10GB is not worth the security risk.

Huge Firmware mess

Your ISP customize the image: why?, how much?, where is the protocol of changes? where is the SBOM? at best you get the formware in an emaail, or from a google drive folder!

Bought in a shop like digitec.ch

You can contact xyzel and hope they will help you, but depending on the provider you still have to contact the provider’s support.

You received the router from Swisscom, Salt, …

You have to use another customized firmware from your provider Security wise a nightmare, all of these provider are behind the curve regarding security and patches.

Swisscom: ftp://[email protected]/AX7501-B0/OBM/V517ABPC1C0.bin login: zyel pwd: zyxel

You received the router from Init7

You can apply C0 (aka default Zyxel firmware), Init7 still customize the firmware.

https://nextcloud.init7.net/s/xaq42XkH8wjt9zc (Passwort: ANbrM7BLG5)

In all cases you have to install an unsigned firmware from your provider ☠️

If you can… some units are locked, you may need to root it first https://th0mas.nl/2020/03/26/getting-root-on-a-zyxel-vmg8825-t50-router/

warning

Again they ask you to DISABLE the firmware ID check with SSH (zycli fwidcheck off) before the update is installed! No word if disabling is persisting after the reboot. What a joke Zyxel do not whitelist and let provider sign a firmware. This company is not serious about security.

ssh 192.168.1.1 -l admin

zycli
zycli modelcheck
zycli modelcheck show (Result : "ret:0")
zycli modelcheck off
zycli modelcheck show (Result : "ret:-17")

zycli fwidcheck show (Result : "ret:0")
zycli fwidcheck off
zycli fwidcheck show (Result : "ret:-17")

exit

What is good in this router?

  • Maybe 5GHz speed in Wifi 6 4800MBit
  • You can request the firmware source code but not do anything with it. Outdated and with binaries whose API can not be upgraded

What is bad in Zyxel AX7501-B0 ?

  • Issues persist with 5GHz connectivity for Mac mini and Apple TV 4K, compelling some users to revert to 2.4GHz.
  • Firmware updates present a challenge due to ISP modifications.
  • Lack of automatic updates or alerts.
  • User interface complexity even for IT professionals.
  • Unstable 5GHz Wi-Fi.
  • Zyxel’s Software Bill of Materials (SBOM) is not public, but revealing outdated and end of life packages.
  • Zyxel neglects security concerns, evident in the absence of SHASUM, untrusted FTP.
  • Inability to disable status LED.
  • Unexplained binary updates from Zyxel.
  • Reliance on a modified OpenWrt version 14.03 instead of the latest 22.03.

I would go as far as to say that this company must be out of business and not supported. Zyxel’s network devices can not be recommended.

Their only solution is to adopt the latest OpenWrt and promote automatic warning or update of their firmware.

if only Apple or Synology would again produce fiber router…

Related content

© 1997 - 2024 Cédric Walter blog

Powered by Open Sources technologies

avatar

Cédric WalterA true selfless act always sparks another

6s a1 acide-hyaluronique acma adaptability advocate-for-change ai airplane algorand alice-hlidkova-author alpine alps altruism-vs-commercialization antique-scooters antiseptic-rinse apache arcade arcade-gaming armattan art artemis artemis-viper artistic-expression atlassian authenticity-in-writing authenticity-matters avis bag bambulab bash bean bennu bernardet bestwishes betaflight betruger beware bien-vivre bien-être bien-être-physique bio bioethics bitcoin blessures-sportives blockchain blockchain-consensus-encyclopedia blockchain-systems blog book-review books bots Bought box brand-authenticity brand-integrity brand-protection breaking-barriers business-management business-milestones business-strategy business-success business-transformation businessbooks byzantine-fault-tolerance calculator calibre calibre-web camera case-studies cc2500 cgm-next challenges changement-de-vie channel-setup cheaper cherry-blossoms chirurgie-orthopédique choosing-fbl-gyro ci/cd classic-games classic-scooters classic-vespa climb climbing codefest collectible-scooters collectibles collection collector color competition consensus-algorithms consensus-mechanisms console consommation-responsable consumer-awareness containerization contest control-surfaces controller copy corticostéroïdes counterfeit-awareness counterfeit-culture counterfeit-market counterfeit-vs-authentic covid19 creating croissance-personnelle cryptocurrency cultural-experience cultural-richness curve-adjustments customer-discovery cve-issues dance-dreams death decentralization decentralized dental-hygiene dependency Design development devfest devops distributed-ledger-technology diverse-perspectives diy-dental diy-health dji docker docker-compose docker-hosting docker-networking docker-registry docker-security dont-buy dotnet Download downloading dreams-and-reality drone dynamic-ip désencombrement développement-personnel développement-spirituel ecology edgetx elrs elta emotional-challenges emotional-hurdles empowering-narrative endpoints engelberg Ensitm entrepreneurial-lessons entrepreneurial-mindset entrepreneurs entrepreneurship entrepreneurship-books Essaim essentially ethereum ethical-dilemmas evoque execution exercices-de-renforcement exercise-form facebook failure-analysis failure-stigma failure-to-success fake fake-apparel fake-brands fake-goods family family-building family-dynamics fashion-ethics fashion-fraud fbl-controllers fbl-system-compatibility fbl-system-features fbl-system-reviews fertility-struggles finance-books finances-personnelles financial-modeling financiallanning firearm firmware-customization firmware-issues fissure-horizontale fitness-routine fitness-tips flexibilité flight-controller flybarless-advantages flybarless-systems foss fpv frame France freestyle fresh-breath friendship-goals front gallery game-music gameplay-mechanics gamer-community games gaming-culture gaming-enthusiast gaming-history gaming-legacy gaming-nostalgia generative-ai genou gestion-de-ladouleur gestion-du-temps git global-impact google green-tea green-tea-mouthwash growth-hacking-books growth-mindset guide hackathon hackday hackfest health-and-wellness helicopter helicopter-community helicopter-gyro helicopter-tuning herbal-mouthwash hewlettpackard historical-scooters hobbies hobby hobbyist-blog holidays holistic-oralcare hollidays home-remedy home-workouts homelab homemade-oralcare honda honesty honey hornet how-to howTo https hugo human-connection hygiene-routine icecream iconic-scooters iflight iflightnazgulevoque immich indoor industrial-shit industry injections-intra-articulaires injury-prevention innovation innovation-books innovation-journey ios japan-travel japanese-cuisine jar java jdk11 jellyfin joint-health junit jupiter kitchen knee-rehabilitation knee-stability knockoff-alert kyoto lacoste lacoste-counterfeit lambretta landmarks leadership leadership-books lean-startup learning-from-failure leg-day leg-workouts legal-complexities legit-fashion let's-encrypt libération life-transformations link linux llm local-traditions m2evo macos magical-adventure magician-lord main make manurhin manurhin-sm75 mapping marathon market-research marketing-books maven me medical medical-advancements metakernel miami-entertainment mid-century-scooters migration mindset-shifts minimalisme minimum-viable-product minty-fresh mixer-settings mk3 mk4 mobilité model-setup modern-family modern-motherhood moon moral-encounters motherhood-dilemmas motorcycle mount mountain mountains mouth-rinse mouthwash-ingredients mouthwash-recipe Mulhouse muscle-activation music mvs mycollection ménisque NASA natural-mouthwash nature nazgul neo-geo-aes neogeo network new-bookrelease nginx-proxy north-face north-face-replica nostalgic-scooters nv14 objectifs old-school-scooters omphobby open-source open-source-rc opensource opentx openvpn oral-care oral-health organizer osaka oss overcoming-challenges p1p p1s parental-rights parenthood-reflections parts passion patella-health persistence personal-relationships photos physical-therapy physiothérapie pivot-strategy pixel-art planet plasma-riche-en-plaquettes platform plex pluto pretty-girl-complex privacy product-market-fit productivity-books proof-of-stake proof-of-work protect-your-style prusa prusa-research public-image quadcopter quadriceps-strength radio-control radio-programming radiomaster rare-scooters raspberrypi raspbian rates-configuration rc rc-community rc-configuration rc-firmware RC helicopter rc-helicopter-electronics rc-helicopter-enthusiasts rc-helicopter-setup rc-helicopter-technology rc-helicopter-tips rc-helicopters rc-modeling rc-simulator realdebrid realflight receiver reflex-xtr refreshing-breath rehabilitation-exercises relations-personnelles relationship-complexities released remote remote-control-flying reproductive-ethics resilience-in-business resilient-women restored-scooters retro-gaming retro-gaming-community retro-gaming-console retro-scooters reverse-proxy rhythms-of-life risk-management robotic router rx réadaptation rééducation sab sab-raw-420 sab-raw-580 sab-raw-700 sales-books santé-articulaire santé-mentale scooter-enthusiast scooter-memorabilia scooters security-nightmare self-leveling-helicopter server-configuration servo-config skydiving snk snk-corporation snk neo geo soap social-issues solex space spams sport ssl-termination ssl/tls startup-books startup-failure static-code-generator steam strategic-networking streaming strength-training success-stories sun support surrogacy-agency surrogacy-journey surrogacy-narratives swiftui swiss switzerland team team-building team-dynamics teeth-cleaning temples-and-shrines tendermint terrot thérapie-physique tokyo torvol traefik traitement-des-fissures transmitter transmitter-firmware travel travel-tips trouver-du-sens tunnel turning-setbacks-into-success tutorial tx unconventional-strategies vacation velosolex vespa viaferrata video video-game-review vintage vintage-scooters vintage-two-wheelers vintage-vespa vintagegaming vmo-exercises warez web-security wind winner winterthur women-supporting-women wordpress workout-progression x1c zurich zyxel zyxel-avoid zyxel-not-serious-with-security zyxel-outdated zyxel-router-not-good équilibre
Me

Cédric Walter is a French-Swiss entrepreneur, investor, and software engineer based in Zurich, Switzerland. He spent his career developing software applications for Swiss insurance companies to handle billions of dollars in premiums. He cofounded Innoveo AG and as the software architect developed the no-code platform designed to reduce the manual coding that powers many software apps. As an active participant in the European hacking community, he works on many open source projects including blockchain. Cédric is a winner of multiple hackathons. His expertise include designing back end, event-based, and blockchain systems. Cédric is also the founded Disruptr GmbH, a software development company that offers full spectrum of services for businesses of all sizes.

JAVA full-stack developer since 2000, in Blockchain since 2017, Certified Scrum Master 2012, Corda Certified Developer in 2019, Ethereum smart contract expert in the SWISS Blockchain Security working group

Hackathons

  • HackZurich 2022 – Level Up in top 25 finalist among 134 submissions
  • SBHACK21 – SwiFi winner of best Solution on Algorand, overall Winner 3rd Prize, CV Labs Fast Track Ticket
  • HackZurich 2020 Europe’s Biggest Hackathon winner in category Migros
  • SBHACK19 – LendIt winner of Swiss biggest Blockchain Hackathon. On chain insurance and ledger for agricultural land soil.
  • Member of the Bitcoin Association Switzerland and Cryptovalley association Switzerland,

PGP: DF52 ADDA C81A 08A6

Copyright information

All editorial content and graphics on our sites are protected by U.S. copyright, international treaties, and other applicable copyright laws and may not be copied without the express permission of Cedric Walter, which reserves all rights. Reuse of any of Cedric Walter editorial content and graphics for any purpose without The author ’s permission is strictly prohibited.

DO NOT copy or adapt the HTML or other code that this site creates to generate pages. It also is covered by copyright.

Reproduction without explicit permission is prohibited. All Rights Reserved. All photos remain copyright © their rightful owners. No copyright infringement is intended.

Disclaimer: The editor(s) reserve the right to edit any comments that are found to be abusive, offensive, contain profanity, serves as spam, is largely self-promotional, or displaying attempts to harbour irrelevant text links for any purpose.

Others

If you like my work or find it helpful, please consider buying me a cup of coffee ☕️. It inspires me to create and maintain more projects in the future. 🦾

It is better to attach some information or leave a message so that I can record the donation 📝 , thank you very much 🙏.

Reproduction without explicit permission is prohibited. All Rights Reserved. All photos remain copyright © their rightful owners. No copyright infringement is intended.