← Back

CVE-2024-40890

nvd nist
Published: Feb 4, 2025Modified: Oct 27, 2025CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Affected (13)

13 products
Vmg1312 B10a Firmware
Vmg1312 B10b Firmware
Vmg1312 B10e Firmware
Vmg3312 B10a Firmware
Vmg3313 B10a Firmware
Vmg3926 B10b Firmware
Vmg4325 B10a Firmware
Vmg4380 B10a Firmware
Vmg8324 B10a Firmware
Vmg8924 B10a Firmware
Sbg3300 N000 Firmware
Sbg3300 Nb00 Firmware
Sbg3500 Nb00 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg1312 B10a
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg1312 B10b
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg1312 B10e
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg3312 B10a
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg3313 B10a
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg3926 B10b
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg4325 B10a
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg4380 B10a
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg8324 B10a
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Vmg8924 B10a
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Sbg3300 N000
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Sbg3300 Nb00
All versions
Configuration M
1 platform
Running on/withPlatform Versions
Zyxel
Sbg3500 N000 Firmware
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Zyxel
Sbg3500 Nb00
All versions

Timeline

No history available yet.