CVE-2024-40890

HIGHCVSS 8.8/10Actively ExploitedEPSS 19.31%

Last modified

CVE-2024-40890 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.. CISA has confirmed active exploitation in the wild. EPSS estimates a 19.31% chance of exploitation in the next 30 days.

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
19.31%

97.0th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelVmg1312-B10a FirmwareAll versions
ZyxelVmg1312-B10b FirmwareAll versions
ZyxelVmg1312-B10e FirmwareAll versions
ZyxelVmg3312-B10a FirmwareAll versions
ZyxelVmg3313-B10a FirmwareAll versions
ZyxelVmg3926-B10b FirmwareAll versions
ZyxelVmg4325-B10a FirmwareAll versions
ZyxelVmg4380-B10a FirmwareAll versions
ZyxelVmg8324-B10a FirmwareAll versions
ZyxelVmg8924-B10a FirmwareAll versions
ZyxelSbg3300-N000 FirmwareAll versions
ZyxelSbg3300-Nb00 FirmwareAll versions
ZyxelSbg3500-N000 FirmwareAll versions
ZyxelSbg3500-Nb00 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-40890?
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
How severe is CVE-2024-40890?
CVE-2024-40890 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 19.31% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2024-40890?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-40890?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST