CVE-2024-40891

HIGH(8.8)KEVErhöhtes Risiko

Zyxel DSL CPE OS Command Injection Vulnerability

Beschreibung

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

KEV-Informationen

Hersteller
Zyxel
Produkt
DSL CPE Devices
Hinzugefügt am
11. Februar 2025
Fälligkeitsdatum
4. März 2025
Erforderliche Maßnahme
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
LOW
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
zyxelvmg1312-b10a firmware-
zyxelvmg1312-b10b firmware-
zyxelvmg1312-b10e firmware-
zyxelvmg3312-b10a firmware-
zyxelvmg3313-b10a firmware-
zyxelvmg3926-b10b firmware-
zyxelvmg4325-b10a firmware-
zyxelvmg4380-b10a firmware-
zyxelvmg8324-b10a firmware-
zyxelvmg8924-b10a firmware-
zyxelsbg3300-n000 firmware-
zyxelsbg3300-nb00 firmware-
zyxelsbg3500-n000 firmware-
zyxelsbg3500-nb00 firmware-

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score22.00%
EPSS-Perzentil97.4%

Daten

Veröffentlicht4. Februar 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.