CVE-2024-40891

CVE Published 2025-02-04
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) zyxel
Related Product(s) vmg8924-b10a_firmware, vmg4325-b10a_firmware, vmg3313-b10a_firmware, vmg8324-b10a_firmware, sbg3500-n000_firmware, vmg1312-b10e_firmware, vmg3926-b10b_firmware, vmg1312-b10a_firmware, sbg3500-nb00_firmware, vmg3312-b10a_firmware, sbg3300-n000_firmware, vmg4380-b10a_firmware, vmg1312-b10b_firmware, sbg3300-nb00_firmware
Exploitation Reported (CISA KEV) 2025-02-11
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

UNSUPPORTED WHEN ASSIGNED A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References