HIGH

CVE-2024-40891

Zyxel Vmg1312 B10a Firmware 2025-02-04 CVSS v3.1
CVSS
8.8
KEV

Description

**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

Summary dbcve.org

A post-authentication command injection vulnerability in the management commands of Zyxel VMG4325-B10A firmware allows authenticated attackers to execute arbitrary OS commands via Telnet. The flaw exists in the legacy DSL CPE's management interface, enabling attackers with valid credentials to inject OS commands through improperly sanitized input.

Mitigation

Since the device is end-of-life and unsupported with no patch available, implement compensating controls: disable Telnet and restrict management interface access to trusted IPs only via firewall rules, or replace the legacy device with a supported model.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

21.54%
Probability of exploitation in next 30 days
97.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE