ZeroHour

CVE-2024-40890

KEVlarge

Authenticated OS Command Injection in Zyxel DSL CPE Devices

CISA: Zyxel DSL CPE OS Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

Multiple Zyxel DSL CPE devices contain an OS command injection flaw (CWE-78) in a CGI program, where insufficient input handling lets a crafted HTTP request execute arbitrary operating-system commands. Because the flaw is post-authentication, an attacker needs valid credentials on the device's web management interface to trigger it, but can then run commands with the privileges of the device's web server, enabling configuration changes, persistence, or pivoting to the ISP subscriber network. Only Zyxel DSL CPE devices are affected; the specific models and firmware versions have not been detailed in the available data, and CISA notes impacted products may be end-of-life or end-of-service. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-11, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been observed. EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile), indicating elevated exploitation risk.

What to do: Inventory all Zyxel DSL CPE devices and check them against Zyxel's advisory to identify affected models, then apply the latest available firmware; since many affected products may be end-of-life or end-of-service, plan replacement or discontinuation of use where no patched firmware or mitigation exists (as CISA's KEV required action directs). In the interim, restrict the device's HTTP/HTTPS management interface to trusted networks, disable remote/WAN-side administration, and ensure strong, non-default admin credentials since exploitation requires authentication.

Affected
Zyxel DSL CPE devices (CGI program in web management interface)
Estimated exposure
largeon the order of hundreds of thousands of deployed Zyxel DSL CPE devices — Zyxel DSL CPEs are widely deployed by ISPs globally and public internet scans historically show very large numbers of exposed Zyxel CPE management interfaces, though the affected model subset (possibly EoL/EoS units) is unspecified, making…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

CISA Known Exploited Vulnerability
Affected
Zyxel DSL CPE Devices
Required action
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
vmg1312-b10a firmware, vmg1312-b10b firmware, vmg1312-b10e firmware, vmg3312-b10a firmware, vmg3313-b10a firmware, vmg3926-b10b firmware, vmg4325-b10a firmware, vmg4380-b10a firmware, vmg8324-b10a firmware, vmg8924-b10a firmware, sbg3300-n000 firmware, sbg3300-nb00 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news