Cyber Posture

CVE-2024-40890

HighCISA KEVActive Exploitation

Published: 04 February 2025

Published
04 February 2025
Modified
27 October 2025
KEV Added
11 February 2025
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.4588 97.6th percentile
Risk Priority 65 60% EPSS · 20% KEV · 20% CVSS

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Security Summary

CVE-2024-40890 is a post-authentication command injection vulnerability (CWE-78) affecting the CGI program in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615. Marked as unsupported when assigned, it enables an authenticated attacker to execute arbitrary operating system commands on the device through a crafted HTTP POST request. The vulnerability carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to network accessibility, low attack complexity, and significant impacts on confidentiality, integrity, and availability.

The attack requires low-privilege authenticated access (PR:L) over the network, with no user interaction needed. An attacker can send a specially crafted HTTP POST request to the vulnerable CGI program, injecting and executing OS commands, potentially leading to full device compromise, including data exfiltration, modification of configurations, or disruption of services.

Zyxel has issued a security advisory addressing this command injection vulnerability alongside insecure default credentials in certain legacy DSL CPE devices. The CVE is also listed in the CISA Known Exploited Vulnerabilities Catalog, signaling real-world exploitation.

Given its presence in the CISA KEV catalog, security practitioners should prioritize identifying and isolating affected legacy devices, as no firmware patches are available for this unsupported version.

Details

CWE(s)
CWE-78
KEV Date Added
11 February 2025

Affected Products

zyxel
vmg1312-b10a firmware
all versions
zyxel
vmg1312-b10b firmware
all versions
zyxel
vmg1312-b10e firmware
all versions
zyxel
vmg3312-b10a firmware
all versions
zyxel
vmg3313-b10a firmware
all versions
zyxel
vmg3926-b10b firmware
all versions
zyxel
vmg4325-b10a firmware
all versions
zyxel
vmg4380-b10a firmware
all versions
zyxel
vmg8324-b10a firmware
all versions
zyxel
vmg8924-b10a firmware
all versions
+4 more product configuration(s) — see NVD for full list

References