ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Swap EOL Zyxel routers, upgrade Netgear ones!

criticalVulnerability exploited in the wildimportance 60CVE-2024-40891CVE-2024-40890CVE-2025-0890

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40890
+1 in the same advisory: …40891
Authenticated OS Command Injection in Zyxel DSL CPE Devices

Multiple Zyxel DSL CPE devices contain an OS command injection flaw (CWE-78) in a CGI program, where insufficient input handling lets a crafted HTTP request execute arbitrary operating-system commands. Because the flaw is post-authentication, an attacker needs valid credentials on the device's web management interface to trigger it, but can then run commands with the privileges of the device's web server, enabling configuration changes, persistence, or pivoting to the ISP subscriber network. Only Zyxel DSL CPE devices are affected; the specific models and firmware versions have not been detailed in the available data, and CISA notes impacted products may be end-of-life or end-of-service. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-11, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been observed. EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile), indicating elevated exploitation risk.

Do: Inventory all Zyxel DSL CPE devices and check them against Zyxel's advisory to identify affected models, then apply the latest available firmware; since many affected products may be end-of-life or end-of-service, plan replacement or discontinuation of use where no patched firmware or mitigation exists (as CISA's KEV required action directs). In the interim, restrict the device's HTTP/HTTPS management interface to trusted networks, disable remote/WAN-side administration, and ensure strong, non-default admin credentials since exploitation requires authentication.

8.822% KEV
  • Zyxel DSL CPE devices (CGI program in web management interface)
largeon the order of hundreds of thousands of deployed Zyxel DSL CPE devices
CVE-2025-0890
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_2017

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

NVD description · AI analysis pending
9.814%
  • zyxel vmg4325-b10a firmware
  • zyxel sbg3500-n000 firmware
  • zyxel vmg1312-b10a firmware
  • +1 more
Full article425 words · extracted from helpnetsecurity.com · click to collapse

There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has confirmed. Meanwhile, Netgear has issued patches for critical flaws affecting its routers and wireless access points.

Zyxel CVE-2024-40891 patches

Zyxel vulnerability: Exploited, no patches

CVE-2024-40891, a command injection vulnerability in Zyxel CPE Series telecommunications devices that has been known since July 2024 and is currently being exploited by attackers, will not be patched by the manufacturer since the affected devices “are legacy products that have reached end-of-life (EOL) for years.”

The affected models are VMG1312-B10A, VMG1312-B10B, VMG1312-B10E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300, and SBG3500.

After the public disclosure of active exploitation, it took Zyxel a whole week to publicly confirm that there won’t be a patch, and advise users to replace the devices with newer-generation products.

“If you obtained your Zyxel product through an internet service provider (ISP), please contact the ISP for support,” they company said.

In what seems like an attempt to deflect responsibility for the slow reaction, Zyxel claims that VulnCheck did not share details about this and two other vulnerabilities – another command injection (CVE-2024-40890) and default credentials (CVE-2025-0890) – when they reported them.

VulnCheck researcher Jacob Baines finally published the details about the three flaws on Monday, and noted that while they have been informed that the affected routers are end-of-life, they are not listed on Zyxel’s EOL page.

“Despite this, both FOFA and Censys identify approximately 1,500 affected systems with internet-facing Telnet interfaces. Additionally, some of these models are still available for purchase through Amazon,” he said.

“While these systems are older and seemingly long out of support, they remain highly relevant due to their continued use worldwide and the sustained interest from attackers. The fact that attackers are still actively exploiting these routers underscores the need for attention, as understanding real-world attacks is critical to effective security research.”

Netgear vulnerabilities: Not exploited, patches available

Netgear has released fixes for two critical remotely exploitable vulnerabilities in its wireless access points and Nighthawk WiFi Pro Gaming router models.

Currently without a CVE number and technical details available, the two vulnerabilities may allow attackers to achieve:

There’s no mention of the vulnerabilities being actively exploited. Nevertheless, the company “strongly recommends” downloading the latest firmware as soon as possible.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/05/swap-eol-zyxel-routers-upgrade-netgear-ones-patches-cve-2024-40891/