LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2024-40891

CVE-2024-40891

Zyxel DSL CPE OS Command Injection Vulnerability

CVSS 8.8 · HIGH ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2025-02-11. Federal remediation due 2025-03-04.
Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

Summary

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

CVSS 3.1 breakdown

Base score8.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Zyxel vmg1312-b10a firmwareZyxel vmg1312-b10aZyxel vmg1312-b10b firmwareZyxel vmg1312-b10bZyxel vmg1312-b10e firmwareZyxel vmg1312-b10eZyxel vmg3312-b10a firmwareZyxel vmg3312-b10aZyxel vmg3313-b10a firmwareZyxel vmg3313-b10aZyxel vmg3926-b10b firmwareZyxel vmg3926-b10bZyxel vmg4325-b10a firmwareZyxel vmg4325-b10aZyxel vmg4380-b10a firmwareZyxel vmg4380-b10aZyxel vmg8324-b10a firmwareZyxel vmg8324-b10aZyxel vmg8924-b10a firmwareZyxel vmg8924-b10a
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-27. Always verify against the vendor advisory before acting.

Scroll to Top