CVE-2024-40891
Description
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
Summary dbcve.org
A post-authentication command injection vulnerability in the management commands of Zyxel VMG4325-B10A firmware allows authenticated attackers to execute arbitrary OS commands via Telnet. The flaw exists in the legacy DSL CPE's management interface, enabling attackers with valid credentials to inject OS commands through improperly sanitized input.
Mitigation
Since the device is end-of-life and unsupported with no patch available, implement compensating controls: disable Telnet and restrict management interface access to trusted IPs only via firewall rules, or replace the legacy device with a supported model.