CVE-2024-40891
KEVmass1Post-Authentication OS Command Injection in Zyxel DSL CPE Devices
CISA: Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication OS command injection flaw (CWE-78) in their management commands. An attacker with valid credentials who can reach the device's management interface over Telnet sends crafted input that is executed as operating-system commands on the device. Successful exploitation yields arbitrary command execution on the CPE, potentially letting an attacker tamper with the gateway or pivot into the subscriber's local network. Organizations and ISPs running affected Zyxel DSL CPEs are exposed if authenticated Telnet management is reachable, and many impacted models may be end-of-life or end-of-service with limited fix options. The flaw was added to CISA's KEV catalog on 2025-02-11, confirming exploitation in the wild, and EPSS gives it a 21.5% chance of exploitation in the next 30 days (97th percentile).
What to do: Inventory your fleet for the affected Zyxel DSL CPE models and check Zyxel's advisory for patched firmware, noting that many impacted models are EoL/EoS and may never receive fixes. Until patched, restrict or disable Telnet-based management — allow it only from trusted management networks — and review logs for unexpected authenticated Telnet sessions or configuration changes. Federal agencies must remediate per KEV timelines; if no mitigation is available on EoL/EoS hardware, discontinue use or plan replacement as CISA recommends.
| Zyxel DSL CPE Devices (multiple models) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
- Affected
- Zyxel DSL CPE Devices
- Required action
- The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- zyxel
- Products
- vmg1312-b10a firmware, vmg1312-b10b firmware, vmg1312-b10e firmware, vmg3312-b10a firmware, vmg3313-b10a firmware, vmg3926-b10b firmware, vmg4325-b10a firmware, vmg4380-b10a firmware, vmg8324-b10a firmware, vmg8924-b10a firmware, sbg3300-n000 firmware, sbg3300-nb00 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H