Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-40891


**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.


Published

2025-02-04T10:15:08.920

Last Modified

2025-02-12T18:11:58.790

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel vmg1312-b10a_firmware - Yes
Hardware zyxel vmg1312-b10a - No
Operating System zyxel vmg1312-b10b_firmware - Yes
Hardware zyxel vmg1312-b10b - No
Operating System zyxel vmg1312-b10e_firmware - Yes
Hardware zyxel vmg1312-b10e - No
Operating System zyxel vmg3312-b10a_firmware - Yes
Hardware zyxel vmg3312-b10a - No
Operating System zyxel vmg3313-b10a_firmware - Yes
Hardware zyxel vmg3313-b10a - No
Operating System zyxel vmg3926-b10b_firmware - Yes
Hardware zyxel vmg3926-b10b - No
Operating System zyxel vmg4325-b10a_firmware - Yes
Hardware zyxel vmg4325-b10a - No
Operating System zyxel vmg4380-b10a_firmware - Yes
Hardware zyxel vmg4380-b10a - No
Operating System zyxel vmg8324-b10a_firmware - Yes
Hardware zyxel vmg8324-b10a - No
Operating System zyxel vmg8924-b10a_firmware - Yes
Hardware zyxel vmg8924-b10a - No
Operating System zyxel sbg3300-n000_firmware - Yes
Hardware zyxel sbg3300-n000 - No
Operating System zyxel sbg3300-nb00_firmware - Yes
Hardware zyxel sbg3300-nb00 - No
Operating System zyxel sbg3500-n000_firmware - Yes
Operating System zyxel sbg3500-n000_firmware - No
Operating System zyxel sbg3500-nb00_firmware - Yes
Hardware zyxel sbg3500-nb00 - No

References