Junglewise Threat Intelligence

CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerability

CVE-2024-40891 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-02-11

Vendors: Zyxel.

Executive brief

Multiple legacy Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in management commands. An authenticated attacker can execute arbitrary operating system commands on the affected device via Telnet.

Affected products

  • Zyxel Corporation VMG4325-B10A firmware 1.00(AAFR.4)C0_20170615
  • Zyxel Corporation SBG3300-N000
  • Zyxel Corporation SBG3300-NB00
  • Zyxel Corporation SBG3500-N000
  • Zyxel Corporation SBG3500-NB00
  • Zyxel Corporation VMG1312-B10A
  • Zyxel Corporation VMG1312-B10B
  • Zyxel Corporation VMG1312-B10E
  • Zyxel Corporation VMG3312-B10A
  • Zyxel Corporation VMG3313-B10A
  • Zyxel Corporation VMG3926-B10B
  • Zyxel Corporation VMG4380-B10A
  • Zyxel Corporation VMG8324-B10A
  • Zyxel Corporation VMG8924-B10A

Timeline

  • 2025-02-04: disclosed: Zyxel security advisory published
  • 2025-02-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats