U.S. CISA adds Microsoft Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40890 +1 in the same advisory: …40891 | Authenticated OS Command Injection in Zyxel DSL CPE Devices Multiple Zyxel DSL CPE devices contain an OS command injection flaw (CWE-78) in a CGI program, where insufficient input handling lets a crafted HTTP request execute arbitrary operating-system commands. Because the flaw is post-authentication, an attacker needs valid credentials on the device's web management interface to trigger it, but can then run commands with the privileges of the device's web server, enabling configuration changes, persistence, or pivoting to the ISP subscriber network. Only Zyxel DSL CPE devices are affected; the specific models and firmware versions have not been detailed in the available data, and CISA notes impacted products may be end-of-life or end-of-service. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-11, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been observed. EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile), indicating elevated exploitation risk. Do: Inventory all Zyxel DSL CPE devices and check them against Zyxel's advisory to identify affected models, then apply the latest available firmware; since many affected products may be end-of-life or end-of-service, plan replacement or discontinuation of use where no patched firmware or mitigation exists (as CISA's KEV required action directs). In the interim, restrict the device's HTTP/HTTPS management interface to trusted networks, disable remote/WAN-side administration, and ensure strong, non-default admin credentials since exploitation requires authentication. | 8.8 | 22% | KEV |
| largeon the order of hundreds of thousands of deployed Zyxel DSL CPE devices | |
| CVE-2025-21418 +1 in the same advisory: …21391 | Local Privilege Escalation via Heap Overflow in Windows WinSock AFD Driver CVE-2025-21418 is a heap-based buffer overflow (CWE-122) in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode driver that services Winsock auxiliary socket operations. A local attacker with limited user privileges can trigger the overflow by issuing crafted Winsock requests to the AFD driver, requiring no user interaction. Successful exploitation elevates the attacker's privileges on the local machine (confidentiality, integrity, and availability all impacted), which is typically used to gain SYSTEM-level control as part of a broader intrusion or ransomware chain. Any system running the affected Windows 10, Windows 11, or Windows Server releases is exposed, since the AFD driver is a core component present on all of them. The flaw was a zero-day exploited in the wild before Microsoft patched it in the February 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-11. Do: Deploy Microsoft's February 2025 Patch Tuesday security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing multi-user servers, jump hosts, and endpoints in ransomware-prone environments since exploitation was already active before patching. Verify deployment through your patch management/SCCM update history; there is no public PoC or known standalone mitigation, so patching is the required action per the CISA KEV entry. | 7.8 group max | 2% | KEV |
| masson the order of 1 billion+ Windows devices (all listed Windows 10/11 client and Windows Server releases) |
Full article521 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 12, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2024-40891 Zyxel DSL CPE OS Command Injection Vulnerability
- CVE-2024-40890 Zyxel DSL CPE OS Command Injection Vulnerability
- CVE-2025-21418 Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
- CVE-2025-21391 Microsoft Windows Storage Link Following Vulnerability
The vulnerability CVE-2024-40891 is a command injection issue in Zyxel CPE Series devices that remains unpatched and has not yet been publicly disclosed. Attackers can exploit this flaw to execute arbitrary commands on affected devices, potentially resulting in device takeover, data exfiltration, or network infiltration.
“CVE-2024-40891 is very similar to CVE-2024-40890 (observed authentication attempts, observed command injection attempts), with the main difference being that the former is telnet-based while the latter is HTTP-based.” reads the advisory published by GreyNoise. “Both vulnerabilities allow unauthenticated attackers to execute arbitrary commands using service accounts (supervisor and/or zyuser).”
VulnCheck disclosed the Zyxel CPE Telnet command injection flaw CVE-2024-40891 on August 1, 2024, but the vendor has yet to publish an advisory. GreyNoise researchers collaborated with VulnCheck to verify the detection and created a tag for the issue on January 21, 2025. Due to widespread attacks, the disclosure was made immediately without vendor coordination.
GreyNoise observed thousands of attack attempts originated from multiple IP addresses, most of them located in Taiwan. Cybersecurity firm Censys reported that more than 1,500 online devices are affected by the vulnerability.
The vulnerability CVE-2024-40890 is a post-authentication command injection issue in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615. An authenticated attacker could exploit the vulnerability to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
The two flaws in Microsoft Windows added to the KeV Catalog were addressed with the release of the Microsoft Patch Tuesday security updates for February 2025. The two zero-day flaws are actively exploited in the wild.
The actively exploited vulnerabilities are a Windows Storage Elevation of Privilege Vulnerability (CVE-2025-21391) and Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2025-21418).
CVE-2025-21391 is a Windows Storage privilege escalation flaw exploited in the wild. It allows attackers to delete files and may be paired with code execution for full system takeover.
“An attacker would only be able to delete targeted files on a system.” reads the advisory. “This vulnerability does not allow disclosure of any confidential information, but could allow an attacker to delete data that could include data that results in the service being unavailable.”
CVE-2025-21418 is a Windows Ancillary Function Driver for WinSock privilege escalation flaw. It could allow an authenticated user to run a crafted program to gain SYSTEM privileges, likely paired with code execution for full system takeover.
“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” reads the advisory.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174135/security/u-s-cisa-adds-microsoft-windows-zyxel-device-flaws-known-exploited-vulnerabilities-catalog.html