Attackers actively exploit a critical zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40890 +1 in the same advisory: …40891 | Authenticated OS Command Injection in Zyxel DSL CPE Devices Multiple Zyxel DSL CPE devices contain an OS command injection flaw (CWE-78) in a CGI program, where insufficient input handling lets a crafted HTTP request execute arbitrary operating-system commands. Because the flaw is post-authentication, an attacker needs valid credentials on the device's web management interface to trigger it, but can then run commands with the privileges of the device's web server, enabling configuration changes, persistence, or pivoting to the ISP subscriber network. Only Zyxel DSL CPE devices are affected; the specific models and firmware versions have not been detailed in the available data, and CISA notes impacted products may be end-of-life or end-of-service. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-11, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been observed. EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile), indicating elevated exploitation risk. Do: Inventory all Zyxel DSL CPE devices and check them against Zyxel's advisory to identify affected models, then apply the latest available firmware; since many affected products may be end-of-life or end-of-service, plan replacement or discontinuation of use where no patched firmware or mitigation exists (as CISA's KEV required action directs). In the interim, restrict the device's HTTP/HTTPS management interface to trusted networks, disable remote/WAN-side administration, and ensure strong, non-default admin credentials since exploitation requires authentication. | 8.8 | 22% | KEV |
| largeon the order of hundreds of thousands of deployed Zyxel DSL CPE devices |
Full article232 words · extracted from securityaffairs.com · click to collapse

Experts warn that threat actors are actively exploiting critical zero-day vulnerability, tracked as CVE-2024-40891, in Zyxel CPE Series devices.
GreyNoise researchers are observing active exploitation attempts targeting a zero-day, tracked as CVE-2024-40891, in Zyxel CPE Series devices.
The vulnerability is a command injection issue that remains unpatched and has not yet been publicly disclosed. Attackers can exploit this flaw to execute arbitrary commands on affected devices, potentially resulting in device takeover, data exfiltration, or network infiltration.
“CVE-2024-40891 is very similar to CVE-2024-40890 (observed authentication attempts, observed command injection attempts), with the main difference being that the former is telnet-based while the latter is HTTP-based.” reads the advisory published by GreyNoise. “Both vulnerabilities allow unauthenticated attackers to execute arbitrary commands using service accounts (supervisor and/or zyuser).”
VulnCheck disclosed the Zyxel CPE Telnet command injection flaw CVE-2024-40891 on August 1, 2024, but the vendor has yet to publish an advisory. GreyNoise researchers collaborated with VulnCheck to verify the detection and created a tag for the issue on January 21, 2025. Due to widespread attacks, the disclosure was made immediately without vendor coordination.
GreyNoise observed thousands of attack attempts originated from multiple IP addresses, most of them located in Taiwan. Cybersecurity firm Censys reported that more than 1,500 online devices are affected by the vulnerability.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2024-40891)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173589/hacking/zyxel-cpe-series-devices-cve-2024-40891-exploited.html