CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-02-11. EPSS: 21.7% chance of exploitation in the next 30 days.

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

Affected products

  • Zyxel SBG3300-n000 Firmware: affected versions not specified
  • Zyxel SBG3300-NB00 Firmware: affected versions not specified
  • Zyxel SBG3500-n000 Firmware: affected versions not specified
  • Zyxel SBG3500-NB00 Firmware: affected versions not specified
  • Zyxel VMG1312-b10a Firmware: affected versions not specified
  • Zyxel VMG1312-b10b Firmware: affected versions not specified
  • Zyxel VMG1312-b10e Firmware: affected versions not specified
  • Zyxel VMG3312-b10a Firmware: affected versions not specified
  • Zyxel VMG3313-b10a Firmware: affected versions not specified
  • Zyxel VMG3926-b10b Firmware: affected versions not specified
  • Zyxel VMG4325-b10a Firmware: affected versions not specified
  • Zyxel VMG4380-b10a Firmware: affected versions not specified
  • Zyxel VMG8324-b10a Firmware: affected versions not specified
  • Zyxel VMG8924-b10a Firmware: affected versions not specified

Published 2025-02-04. Last modified 2026-06-17.