Executive brief
Multiple legacy Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in management commands. An authenticated attacker can execute arbitrary operating system commands on the affected device via Telnet.
Affected products
- Zyxel Corporation VMG4325-B10A firmware 1.00(AAFR.4)C0_20170615
- Zyxel Corporation SBG3300-N000
- Zyxel Corporation SBG3300-NB00
- Zyxel Corporation SBG3500-N000
- Zyxel Corporation SBG3500-NB00
- Zyxel Corporation VMG1312-B10A
- Zyxel Corporation VMG1312-B10B
- Zyxel Corporation VMG1312-B10E
- Zyxel Corporation VMG3312-B10A
- Zyxel Corporation VMG3313-B10A
- Zyxel Corporation VMG3926-B10B
- Zyxel Corporation VMG4380-B10A
- Zyxel Corporation VMG8324-B10A
- Zyxel Corporation VMG8924-B10A
Timeline
- 2025-02-04: disclosed: Zyxel security advisory published
- 2025-02-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog