CVE Feed

    Dashboard / CVE / CVE-2024-40891

    CVE-2024-40891

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

    Published:Feb 4, 2025
    Last Modified:Oct 27, 2025
    EPS:Feb 4, 2025
    EPSS Score:0.49732
    CVSS Score:8.8

    CISA Notification

    Description

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

    Required Action:

    The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Mar 4, 2025
    556 days ago
    Alert Date
    Feb 11, 2025
    577 days ago

    Affected Products

    Vendor
    Zyxel
    Product
    Sbg3300-n000
    Vendor
    Zyxel
    Product
    Sbg3300-n000 Firmware
    Vendor
    Zyxel
    Product
    Sbg3300-nb00
    Vendor
    Zyxel
    Product
    Sbg3300-nb00 Firmware
    Vendor
    Zyxel
    Product
    Sbg3500-n000 Firmware
    Vendor
    Zyxel
    Product
    Sbg3500-nb00
    Vendor
    Zyxel
    Product
    Sbg3500-nb00 Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10a
    Vendor
    Zyxel
    Product
    Vmg1312-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10b
    Vendor
    Zyxel
    Product
    Vmg1312-b10b Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10e
    Vendor
    Zyxel
    Product
    Vmg1312-b10e Firmware
    Vendor
    Zyxel
    Product
    Vmg3312-b10a
    Vendor
    Zyxel
    Product
    Vmg3312-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg3313-b10a
    Vendor
    Zyxel
    Product
    Vmg3313-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg3926-b10b
    Vendor
    Zyxel
    Product
    Vmg3926-b10b Firmware
    Vendor
    Zyxel
    Product
    Vmg4325-b10a
    Vendor
    Zyxel
    Product
    Vmg4325-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg4380-b10a
    Vendor
    Zyxel
    Product
    Vmg4380-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg8324-b10a
    Vendor
    Zyxel
    Product
    Vmg8324-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg8924-b10a
    Vendor
    Zyxel
    Product
    Vmg8924-b10a Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High