SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-40890

Zyxel DSL CPE OS Command Injection Vulnerability

KEVHIGH 8.8EPSS 22.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
22.25% probability · 98th percentile
CISA KEV
Listed 11 February 2025 · due 4 March 2025
Weakness
CWE-78
Affected
zyxel/vmg1312-b10a firmware · zyxel/vmg1312-b10b firmware · zyxel/vmg1312-b10e firmware · zyxel/vmg3312-b10a firmware · zyxel/vmg3313-b10a firmware · zyxel/vmg3926-b10b firmware · zyxel/vmg4325-b10a firmware · zyxel/vmg4380-b10a firmware · zyxel/vmg8324-b10a firmware · zyxel/vmg8924-b10a firmware · zyxel/sbg3300-n000 firmware · zyxel/sbg3300-nb00 firmware · zyxel/sbg3500-n000 firmware · zyxel/sbg3500-nb00 firmware
Source
security@zyxel.com.tw

CISA notes

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 ; https://www.zyxel.com/service-provider/global/en/security-advisories/zyxel-security-advisory-command-injection-insecure-in-certain-legacy-dsl-cpe-02-04-2025 ; https://nvd.nist.gov/vuln/detail/CVE-2024-40890

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.