Junglewise Threat Intelligence

CVE-2024-40890: Zyxel DSL CPE OS Command Injection Vulnerability

CVE-2024-40890 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-02-11

Vendors: Zyxel.

Executive brief

A post-authentication command injection vulnerability in the CGI program of several legacy Zyxel DSL CPE devices allows an authenticated attacker to execute arbitrary operating system commands via crafted HTTP POST requests. The vulnerability affects multiple end-of-life models including the VMG and SBG series.

Affected products

  • Zyxel VMG4325-B10A firmware 1.00(AAFR.4)C0_20170615
  • Zyxel SBG3300-N000
  • Zyxel SBG3300-NB00
  • Zyxel SBG3500-N000
  • Zyxel SBG3500-NB00
  • Zyxel VMG1312-B10A
  • Zyxel VMG1312-B10B
  • Zyxel VMG1312-B10E
  • Zyxel VMG3312-B10A
  • Zyxel VMG3313-B10A
  • Zyxel VMG3926-B10B
  • Zyxel VMG4380-B10A
  • Zyxel VMG8324-B10A
  • Zyxel VMG8924-B10A

Timeline

  • 2025-02-04: disclosed: Vendor advisory published by Zyxel
  • 2025-02-11: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-02-11: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats