CVE-2024-40891
Zyxel DSL CPE OS Command Injection Vulnerability
Description
CVE-2024-40891 is a high-severity post-authentication command injection vulnerability in legacy Zyxel DSL CPE devices, specifically the VMG4325-B10A and other legacy DSL models. The flaw exists in the management commands accessible via Telnet, allowing an authenticated attacker to execute arbitrary operating system commands on the affected device. With a CVSS v3.1 base score of 8.8 and an EPSS score of 39.30% at the 97th percentile, this vulnerability presents a critical exploitation risk. CISA has added CVE-2024-40891 to the Known Exploited Vulnerabilities catalog with a remediation deadline of March 4, 2025. Notably, this vulnerability affects end-of-life devices that are no longer supported by Zyxel.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| zyxel | vmg1312-b10a firmware | - |
| zyxel | vmg1312-b10b firmware | - |
| zyxel | vmg1312-b10e firmware | - |
| zyxel | vmg3312-b10a firmware | - |
| zyxel | vmg3313-b10a firmware | - |
| zyxel | vmg3926-b10b firmware | - |
| zyxel | vmg4325-b10a firmware | - |
| zyxel | vmg4380-b10a firmware | - |
| zyxel | vmg8324-b10a firmware | - |
| zyxel | vmg8924-b10a firmware | - |
| zyxel | sbg3300-n000 firmware | - |
| zyxel | sbg3300-nb00 firmware | - |
| zyxel | sbg3500-n000 firmware | - |
| zyxel | sbg3500-nb00 firmware | - |
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40891(US Government Resource)
Weakness Type
Command Injection in Management Interface
CVE-2024-40891 arises from a command injection weakness in the Telnet-based management interface of legacy Zyxel DSL CPE devices. While no specific CWE has been formally assigned, the vulnerability aligns with OS command injection patterns where user-supplied input is incorporated into operating system commands without proper sanitization or validation. An authenticated attacker can inject arbitrary OS commands through the Telnet management interface, which are then executed with the privileges of the underlying system process handling the management commands.
Impact Analysis
CVE-2024-40891 represents a severe threat to organizations and individuals still operating legacy Zyxel DSL CPE devices. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates the vulnerability is exploitable over the network with low attack complexity and requires only low-level (standard user) authentication. Confidentiality (High): Successful exploitation grants the attacker full access to the device's configuration, stored credentials, network traffic passing through the router, and any sensitive data accessible from the device's vantage point on the network. Integrity (High): Arbitrary command execution allows an attacker to modify device configurations, alter DNS settings to redirect traffic, install persistent backdoors, modify firmware, or use the compromised device as a pivot point for attacks on the internal network. Availability (High): The attacker can disrupt network connectivity by crashing the device, altering routing tables, or rendering the device inoperable. The EPSS score of 39.30% at the 97th percentile indicates a very high probability of active exploitation. The fact that these are end-of-life, unsupported devices significantly compounds the risk, as no official patches will be provided. The ransomware association is currently listed as unknown, but compromised edge devices are frequently used as entry points for ransomware campaigns.
Exploit Maturity
CVE-2024-40891 exhibits high exploit maturity with confirmed active exploitation in the wild. CISA has added this vulnerability to the Known Exploited Vulnerabilities catalog, confirming that threat actors are actively targeting legacy Zyxel DSL CPE devices through this command injection flaw, with a mandatory remediation deadline of March 4, 2025. The EPSS score of 39.30% at the 97th percentile places this among the most likely-to-be-exploited vulnerabilities currently tracked. The combination of a network-accessible Telnet management interface, low-privilege authentication requirements, and the widespread deployment of these legacy DSL devices makes this vulnerability particularly attractive to attackers. The fact that affected devices are end-of-life and will receive no further security updates from Zyxel increases the long-term exploitation risk. Ransomware use is currently listed as unknown.
Remediation
-
Replace affected end-of-life devices immediately. Zyxel has explicitly stated that the affected DSL CPE devices (VMG1312-B10A/B/E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300-N/NB00, SBG3500-N/NB00) are legacy products that have reached end-of-life status and will not receive patches. The primary recommended action is to replace these devices with current, supported models. Consult the Zyxel security advisory for details.
-
Disable Telnet management access. If immediate device replacement is not possible, disable the Telnet management interface on all affected devices to eliminate the attack vector. Use only encrypted management protocols where available, or restrict management access to local console connections only.
-
Restrict network access to management interfaces. Implement firewall rules and access control lists to block remote access to the Telnet management port (typically port 23) from untrusted networks, including the internet. Ensure management interfaces are only accessible from a dedicated, isolated management VLAN.
-
Monitor for indicators of compromise. Review device logs and network traffic for unusual Telnet sessions, unexpected commands, or anomalous outbound connections from the affected devices. Deploy network intrusion detection signatures targeting command injection patterns on Telnet sessions to legacy Zyxel devices.
-
Conduct a network audit for legacy devices. Inventory all network edge devices across the organization to identify any additional end-of-life Zyxel DSL CPE equipment. Establish a replacement timeline for all legacy devices and implement a lifecycle management policy that ensures timely retirement of unsupported network equipment.
Technical Details
CVE-2024-40891 is a post-authentication command injection vulnerability in the Telnet management interface of legacy Zyxel DSL CPE devices. The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates the vulnerability is exploitable remotely over the network with low complexity, requiring only low-privilege authentication and no user interaction. The scope is unchanged, with maximum impact across confidentiality, integrity, and availability. The root cause resides in the management command processing logic of the Telnet service. When an authenticated user submits commands through the Telnet management interface, the device's firmware fails to properly sanitize or validate command parameters before passing them to the underlying operating system shell for execution. This allows an attacker who has authenticated with even basic user credentials to inject arbitrary operating system commands by embedding shell metacharacters or additional commands within management command parameters. The injected commands execute with the privileges of the process handling the Telnet management session, which typically runs with root or equivalent elevated privileges on embedded Linux-based firmware. The vulnerability was specifically identified in the Zyxel VMG4325-B10A with firmware version 1.00(AAFR.4)C0_20170615, but the advisory confirms that numerous other legacy VMG and SBG series devices share the same vulnerable codebase.
Frequently Asked Questions
Is CVE-2024-40891 being actively exploited?
Yes. CISA has confirmed active exploitation in the wild by adding CVE-2024-40891 to the Known Exploited Vulnerabilities catalog with a mandatory remediation deadline of March 4, 2025. The EPSS score of 39.30% at the 97th percentile further confirms that this is among the most actively targeted vulnerabilities currently tracked.
Will Zyxel release a patch for CVE-2024-40891?
No. The affected devices are legacy products that have reached end-of-life status. Zyxel has stated that these devices will not receive security patches. The recommended action is to replace affected devices with current, supported models. See the Zyxel security advisory for guidance on replacement options.
What Zyxel devices are affected by CVE-2024-40891?
The vulnerability affects numerous legacy Zyxel DSL CPE devices including the VMG1312-B10A/B/E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300-N000/NB00, and SBG3500-N000/NB00. All of these are end-of-life products.
How can I mitigate CVE-2024-40891 if I cannot immediately replace the device?
As an interim measure, disable the Telnet management interface entirely and restrict all management access to the device using firewall rules that block remote access to management ports. Monitor the device for signs of compromise and plan for device replacement as the highest priority action.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.