CVE-2024-40890
Zyxel DSL CPE OS Command Injection Vulnerability
Description
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Severity: HIGH
CVSS Score: 8.8
Vendor: Zyxel
Product: DSL CPE Devices
Loading CVE details...