CVE-2024-40891 is a post-authentication command injection vulnerability affecting the Zyxel VMG4325-B10A DSL CPE device, specifically firmware version 1.00(AAFR.4)C0_20170615. An authenticated attacker can exploit this flaw via Telnet to execute arbitrary operating system commands on the device. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vendor has stated that the affected product is unsupported and will not receive a patch. CVE-2024-40891 is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and extensive media coverage. Despite no public Metasploit or Nuclei modules, the vulnerability has garnered significant community discussion, highlighting its active exploitation and the lack of a vendor-provided fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE
Feb 4, 2025Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE
Feb 4, 2025