Fiche vulnérabilité
CVE-2024-40890 : faille exploitée zyxel vmg1312-b10a firmware (CVSS 8.8)
Description
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 4 févr. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zyxel vmg1312-b10a firmware
- zyxel vmg1312-b10b firmware
- zyxel vmg1312-b10e firmware
- zyxel vmg3312-b10a firmware
- zyxel vmg3313-b10a firmware
- zyxel vmg3926-b10b firmware
- zyxel vmg4325-b10a firmware
- zyxel vmg4380-b10a firmware
- zyxel vmg8324-b10a firmware
- zyxel vmg8924-b10a firmware
- zyxel sbg3300-n000 firmware
- zyxel sbg3300-nb00 firmware
- zyxel sbg3500-n000 firmware
- zyxel sbg3500-nb00 firmware
Correctif et mesures
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.