CVE-2024-40890

HIGH(8.8)KEVElevated Risk

Zyxel DSL CPE OS Command Injection Vulnerability

Description

CVE-2024-40890 is a high-severity post-authentication command injection vulnerability in the CGI program of legacy Zyxel DSL CPE devices, including the VMG4325-B10A and other legacy DSL models. The flaw allows an authenticated attacker to execute arbitrary operating system commands by sending a crafted HTTP POST request to the device's web management interface. With a CVSS v3.1 base score of 8.8 and an EPSS score of 13.04% at the 93rd percentile, this vulnerability presents a significant exploitation risk. CISA has added CVE-2024-40890 to the Known Exploited Vulnerabilities catalog with a remediation deadline of March 4, 2025, and the affected devices are end-of-life products that will not receive patches from Zyxel.

KEV Information

Vendor
Zyxel
Product
DSL CPE Devices
Date Added
February 11, 2025
Due Date
March 4, 2025
Required Action
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
zyxelvmg1312-b10a firmware-
zyxelvmg1312-b10b firmware-
zyxelvmg1312-b10e firmware-
zyxelvmg3312-b10a firmware-
zyxelvmg3313-b10a firmware-
zyxelvmg3926-b10b firmware-
zyxelvmg4325-b10a firmware-
zyxelvmg4380-b10a firmware-
zyxelvmg8324-b10a firmware-
zyxelvmg8924-b10a firmware-
zyxelsbg3300-n000 firmware-
zyxelsbg3300-nb00 firmware-
zyxelsbg3500-n000 firmware-
zyxelsbg3500-nb00 firmware-

References

Weakness Type

Command Injection in CGI Program

CVE-2024-40890 arises from a command injection weakness in the CGI program of the web management interface on legacy Zyxel DSL CPE devices. While no specific CWE has been formally assigned, the vulnerability aligns with OS command injection patterns where HTTP POST parameters are incorporated into operating system commands without proper sanitization. The CGI program on affected Zyxel devices fails to validate or escape user-supplied input from POST requests, allowing an authenticated attacker to inject and execute arbitrary commands on the underlying operating system.

Impact Analysis

CVE-2024-40890 represents a critical risk to organizations and individuals operating legacy Zyxel DSL CPE devices. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates the vulnerability is exploitable over the network with low attack complexity, requiring only low-privilege authentication and no user interaction. Confidentiality (High): An attacker achieving command execution can access all configuration data, stored credentials, and network traffic traversing the device, potentially capturing sensitive communications and authentication tokens for connected systems. Integrity (High): Arbitrary command execution enables the attacker to modify device configurations, alter DNS records to redirect traffic, install persistent malware or rootkits, and use the compromised router as a launching point for further attacks against the internal network. Availability (High): The attacker can disable network services, crash the device, corrupt firmware, or render the device permanently inoperable. The EPSS score of 13.04% at the 93rd percentile indicates elevated exploitation probability. Since these are end-of-life devices with no available patches, the risk persists indefinitely for any organization that continues to use the affected hardware. Ransomware association is currently listed as unknown, but compromised network edge devices frequently serve as initial access vectors in ransomware campaigns.

Exploit Maturity

CVE-2024-40890 shows significant exploit maturity with confirmed active exploitation. CISA has added this vulnerability to the Known Exploited Vulnerabilities catalog, confirming that threat actors are actively targeting the web management interface of legacy Zyxel DSL CPE devices, with a mandatory remediation deadline of March 4, 2025. The EPSS score of 13.04% at the 93rd percentile indicates a substantially elevated likelihood of exploitation compared to the general vulnerability population. This vulnerability is closely related to CVE-2024-40891, which targets the same class of devices through their Telnet interface rather than the web CGI program, suggesting that attackers are systematically exploiting multiple entry points on these legacy devices. The combination of HTTP-based exploitation (more commonly accessible than Telnet), low authentication requirements, and the widespread deployment of unsupported Zyxel DSL equipment makes this a high-priority threat. Ransomware use is currently listed as unknown.

Remediation

  1. Replace affected end-of-life devices immediately. Zyxel has confirmed that the vulnerable DSL CPE devices (VMG1312-B10A/B/E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300-N/NB00, SBG3500-N/NB00) have reached end-of-life and will not receive security patches. The primary remediation is to replace these devices with supported models. Refer to the Zyxel security advisory for complete details.

  2. Disable or restrict the web management interface. If immediate replacement is not feasible, disable remote access to the web management interface on all affected devices. Configure firewall rules to block HTTP/HTTPS access to the device management port from untrusted networks, permitting only local administration from a secure management workstation.

  3. Implement network segmentation for legacy devices. Place affected Zyxel devices on isolated network segments with strict access controls. Deploy a separate firewall or access control device upstream of the vulnerable equipment to filter and monitor all traffic to and from the management interface.

  4. Monitor for signs of compromise. Inspect device logs for unusual HTTP POST requests to CGI endpoints, unexpected configuration changes, or anomalous outbound connections. Deploy network intrusion detection rules to identify command injection patterns in HTTP traffic directed at Zyxel device management interfaces.

  5. Audit and retire all legacy network equipment. Conduct a comprehensive inventory of all network devices to identify end-of-life equipment. Develop and execute a migration plan to replace all unsupported devices with current, vendor-supported alternatives that receive regular security updates.

Technical Details

CVE-2024-40890 is a post-authentication command injection vulnerability in the CGI program of the web management interface on legacy Zyxel DSL CPE devices. The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates the vulnerability is network-exploitable with low complexity, requires only low-privilege authentication, and achieves maximum impact on confidentiality, integrity, and availability without requiring user interaction. The technical root cause lies in the CGI program that processes HTTP POST requests on the device's web management interface. When an authenticated user submits form data or API requests through the web interface, certain POST parameters are passed directly to operating system command execution functions without adequate input validation, escaping, or parameterization. An attacker can embed shell metacharacters and additional operating system commands within crafted HTTP POST parameters. The CGI program passes these unsanitized parameters to the system shell, where the injected commands are interpreted and executed with the elevated privileges of the web server process. The vulnerability was confirmed in the Zyxel VMG4325-B10A running firmware version 1.00(AAFR.4)C0_20170615, but the same vulnerable CGI codebase is shared across multiple legacy VMG and SBG series devices, extending the attack surface to all listed affected models.

Frequently Asked Questions

Is CVE-2024-40890 being actively exploited?

Yes. CISA has confirmed active exploitation in the wild by including CVE-2024-40890 in the Known Exploited Vulnerabilities catalog with a remediation deadline of March 4, 2025. The EPSS score of 13.04% at the 93rd percentile indicates a significantly elevated exploitation probability compared to the average vulnerability.

How is CVE-2024-40890 different from CVE-2024-40891?

Both vulnerabilities affect the same legacy Zyxel DSL CPE devices and enable command injection, but they exploit different management interfaces. CVE-2024-40890 targets the web management CGI program through crafted HTTP POST requests, while CVE-2024-40891 targets the Telnet management interface. Both require authentication and can achieve arbitrary command execution.

Will Zyxel provide a patch for CVE-2024-40890?

No. All affected devices are legacy products that have reached end-of-life. Zyxel has confirmed that no patches will be released. The recommended action is to replace the affected devices with current, supported models that receive ongoing security updates.

What should I do if I cannot immediately replace my affected Zyxel device?

Disable remote access to the web management interface and restrict all management traffic using upstream firewall rules. Change all default credentials on the device, monitor for indicators of compromise, and prioritize device replacement as soon as possible.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score22.25%
EPSS Percentile97.5%

Dates

PublishedFebruary 4, 2025
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.