8.8

CVE-2024-40890

Warnung

**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelVmg1312-b10a Firmware Version-
   ZyxelVmg1312-b10a Version-
ZyxelVmg1312-b10b Firmware Version-
   ZyxelVmg1312-b10b Version-
ZyxelVmg1312-b10e Firmware Version-
   ZyxelVmg1312-b10e Version-
ZyxelVmg3312-b10a Firmware Version-
   ZyxelVmg3312-b10a Version-
ZyxelVmg3313-b10a Firmware Version-
   ZyxelVmg3313-b10a Version-
ZyxelVmg3926-b10b Firmware Version-
   ZyxelVmg3926-b10b Version-
ZyxelVmg4325-b10a Firmware Version-
   ZyxelVmg4325-b10a Version-
ZyxelVmg4380-b10a Firmware Version-
   ZyxelVmg4380-b10a Version-
ZyxelVmg8324-b10a Firmware Version-
   ZyxelVmg8324-b10a Version-
ZyxelVmg8924-b10a Firmware Version-
   ZyxelVmg8924-b10a Version-
ZyxelSbg3300-n000 Firmware Version-
   ZyxelSbg3300-n000 Version-
ZyxelSbg3300-nb00 Firmware Version-
   ZyxelSbg3300-nb00 Version-
ZyxelSbg3500-n000 Firmware Version-
   ZyxelSbg3500-n000 Firmware Version-
ZyxelSbg3500-nb00 Firmware Version-
   ZyxelSbg3500-nb00 Version-

11.02.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zyxel DSL CPE OS Command Injection Vulnerability

Schwachstelle

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.

Beschreibung

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 24.08% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.