ZeroHour

CVE-2024-40891

KEVmass1

Post-Authentication OS Command Injection in Zyxel DSL CPE Devices

CISA: Zyxel DSL CPE OS Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
22%p97
Published
()
KEV added
AI analysis

Multiple Zyxel DSL CPE devices contain a post-authentication OS command injection flaw (CWE-78) in their management commands. An attacker with valid credentials who can reach the device's management interface over Telnet sends crafted input that is executed as operating-system commands on the device. Successful exploitation yields arbitrary command execution on the CPE, potentially letting an attacker tamper with the gateway or pivot into the subscriber's local network. Organizations and ISPs running affected Zyxel DSL CPEs are exposed if authenticated Telnet management is reachable, and many impacted models may be end-of-life or end-of-service with limited fix options. The flaw was added to CISA's KEV catalog on 2025-02-11, confirming exploitation in the wild, and EPSS gives it a 21.5% chance of exploitation in the next 30 days (97th percentile).

What to do: Inventory your fleet for the affected Zyxel DSL CPE models and check Zyxel's advisory for patched firmware, noting that many impacted models are EoL/EoS and may never receive fixes. Until patched, restrict or disable Telnet-based management — allow it only from trusted management networks — and review logs for unexpected authenticated Telnet sessions or configuration changes. Federal agencies must remediate per KEV timelines; if no mitigation is available on EoL/EoS hardware, discontinue use or plan replacement as CISA recommends.

Affected
Zyxel DSL CPE Devices (multiple models)
Estimated exposure
mass≈1M+ deployed units worldwide, though the directly exploitable subset (Telnet-reachable with valid credentials) is unknown — Zyxel has historically been a top-tier supplier of DSL customer-premises equipment to internet service providers, whose managed deployments typically run to millions of units, but the source data contains no per-model install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

CISA Known Exploited Vulnerability
Affected
Zyxel DSL CPE Devices
Required action
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
vmg1312-b10a firmware, vmg1312-b10b firmware, vmg1312-b10e firmware, vmg3312-b10a firmware, vmg3313-b10a firmware, vmg3926-b10b firmware, vmg4325-b10a firmware, vmg4380-b10a firmware, vmg8324-b10a firmware, vmg8924-b10a firmware, sbg3300-n000 firmware, sbg3300-nb00 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news