CVE-2024-11253: Zyxel DM4200-b0 Firmware

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.

Affected products

  • Zyxel DM4200-b0 Firmware: up to and including 5.17\(acbs.1\)c0
  • Zyxel EMG5723-t50k Firmware: up to and including 5.50\(abom.8.5\)c0
  • Zyxel VMG3927-t50k Firmware: up to and including 5.50\(abom.8.5\)c0
  • Zyxel VMG4005-b50a Firmware: up to and including 5.15\(abqa.2.3\)c0
  • Zyxel VMG4005-b60a Firmware: up to and including 5.15\(abqa.2.3\)c0
  • Zyxel VMG8825-t50k Firmware: up to and including 5.50\(abom.8.5\)c0

Published 2025-03-11. Last modified 2026-06-17.