CVE-2024-40890

CVE Published 2025-02-04
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) zyxel
Related Product(s) vmg8924-b10a_firmware, vmg4325-b10a_firmware, vmg3313-b10a_firmware, vmg8324-b10a_firmware, sbg3500-n000_firmware, vmg1312-b10e_firmware, vmg3926-b10b_firmware, sbg3300-n000_firmware, sbg3500-nb00_firmware, vmg1312-b10a_firmware, vmg3312-b10a_firmware, vmg4380-b10a_firmware, vmg1312-b10b_firmware, sbg3300-nb00_firmware
Exploitation Reported (CISA KEV) 2025-02-11
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

UNSUPPORTED WHEN ASSIGNED A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References