CVE-2024-40890
published 2025-02-04CVE-2024-40890: **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware…
PriorityP188high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-03-04
Exploited in the wild
EPSS
20.12%
97.1th percentile
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | vmg4325-b10a_firmware | <= 1.00(AAFR.4)C0_20170615 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel DSL CPE Authenticated HTTP Command Injection (CVE-2024-40890)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/pages/tabFW/disagnostic-general.cgi"; fast_pattern; http.request_body; content:"diagAddr|3d|"; pcre:"/^(?:\d+\x2e){3}\d+[\x0d\x0a]+[\w\x2f]+\x2b/R"; reference:url,vulncheck.com/blog/zyxel-http-vuln#cve-2024-40890-authenticated-http-vulnerability; reference:cve,2024-40890; classtype:web-application-attack; sid:2060109; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2024_40890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2025_02_14; target:dest_ip;)- →The exploit targets the CGI endpoint /pages/tabFW/disagnostic-general.cgi via HTTP POST with a crafted diagAddr parameter containing shell metacharacters for command injection. ↗
- →CVE-2024-40890 is HTTP-based; its sibling CVE-2024-40891 is telnet-based. Both allow command injection via service accounts (supervisor and/or zyuser). Monitor for unusual telnet requests to Zyxel CPE management interfaces as a parallel detection surface. ↗
- →Exploitation of CVE-2024-40891 (telnet variant) has been incorporated into Mirai botnet strains; overlap between exploiting IPs and Mirai-classified IPs was confirmed. Treat Mirai C2 blocklists as a supplementary detection layer for the same device population. ↗
- →Vulnerable firmware version confirmed in PoC: VMG4325-B10A running 1.00(AAFR.4)C0_20170615. Use this version string to identify exposed assets via banner/version scanning. ↗
- →Weak default credentials are a prerequisite for exploitation (CVE-2025-0890): admin:1234, zyuser:1234, supervisor:zyad1234. The supervisor account carries hidden elevated privileges enabling full system access. ↗
- →Improper command validation in libcms_cli.so allows shell metacharacters to be passed unchecked to a shell execution function. Detection of shell metacharacter sequences in telnet/HTTP management traffic to these devices is a strong indicator of exploitation. ↗
- ·The Snort/ET rule (sid:2060109) targets the HTTP-based CVE-2024-40890 variant only; a separate detection strategy is needed for the telnet-based CVE-2024-40891 sibling vulnerability, which is the one actively exploited in the wild at scale. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r9jg-gp7p-hp34: **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmwa
ghsa_unreviewed·2025-02-04
CVE-2024-40890 [HIGH] CWE-78 GHSA-r9jg-gp7p-hp34: **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmwa
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
VulnCheck
Zyxel DSL CPE OS Command Injection Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-40890 [HIGH] CWE-78 Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Affected: Zyxel DSL CPE Devices
Required Action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Exploitation References: https://www.greynoise.io/blog/active-exploitation-of-zero-day-zyxel-cpe-vulnerability-cve-2024-40891; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Remediation Due: 2025-03-04
CISA
Zyxel DSL CPE OS Command Injection Vulnerability
cisa·2025-02-11·CVSS 8.8
CVE-2024-40890 [HIGH] CWE-78 Zyxel DSL CPE OS Command Injection Vulnerability
Vulnerability: Zyxel DSL CPE OS Command Injection Vulnerability
Affected: Zyxel DSL CPE Devices
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Required Action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 ; https://www.zyxel.com/service-provider/global/en/security-advisories/zyxel-security-advisory-command-injection-inse
Suricata
ET WEB_SPECIFIC_APPS Zyxel DSL CPE Authenticated HTTP Command Injection (CVE-2024-40890)
suricata·2025-02-14·CVSS 8.8
CVE-2024-40890 [HIGH] ET WEB_SPECIFIC_APPS Zyxel DSL CPE Authenticated HTTP Command Injection (CVE-2024-40890)
ET WEB_SPECIFIC_APPS Zyxel DSL CPE Authenticated HTTP Command Injection (CVE-2024-40890)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel DSL CPE Authenticated HTTP Command Injection (CVE-2024-40890)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/pages/tabFW/disagnostic-general.cgi"; fast_pattern; http.request_body; content:"diagAddr|3d|"; pcre:"/^(?:\d+\x2e){3}\d+[\x0d\x0a]+[\w\x2f]+\x2b/R"; reference:url,vulncheck.com/blog/zyxel-http-vuln#cve-2024-40890-authenticated-http-vulnerability; reference:cve,2024-40890; classtype:web-application-attack; sid:2060109; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2024_40890, deployment Perimeter, deployment Internal, co
No public exploits indexed.
Bleepingcomputer
Zyxel won’t patch newly exploited flaws in end-of-life routers
blogs_bleepingcomputer·2025-02-04·CVSS 8.8
CVE-2024-40891 [HIGH] Zyxel won’t patch newly exploited flaws in end-of-life routers
## Zyxel won’t patch newly exploited flaws in end-of-life routers
## Bill Toulas
In a new post today, VulnCheck presented the full details of the two flaws it observed in attacks aimed at gaining initial access to networks:
CVE-2024-40891 – Authenticated users can exploit Telnet command injection due to improper command validation in libcms_cli.so. Certain commands (e.g., ifconfig, ping, tftp) are passed unchecked to a shell execution function, allowing arbitrary code execution using shell metacharacters.
CVE-2025-0890 – Devices use weak default credentials (admin:1234, zyuser:1234, supervisor:zyad1234), which many users don't change. The supervisor account has hidden privileges, granting full system access, while zyuser can exploit CVE-2024-40891 for remote code execution.
VulnCheck
Bleepingcomputer
Hackers exploit critical unpatched flaw in Zyxel CPE devices
blogs_bleepingcomputer·2025-01-29·CVSS 8.8
CVE-2024-40891 [HIGH] Hackers exploit critical unpatched flaw in Zyxel CPE devices
## Hackers exploit critical unpatched flaw in Zyxel CPE devices
## Bill Toulas
Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July.
The vulnerability allows unauthenticated attackers to execute arbitrary commands using the ‘supervisor’ or ‘zyuser’ service accounts.
Vulnerability intelligence company VulnCheck added the security issue to its database last year on July 12 and listed it among other issues exploited in the wild for initial access.
Technical details on the vulnerability have not been publicly disclosed and Zyxel did not release a security advisory or a patch for CVE-2024-40891, and the issue remains exploitable in the latest firmware.
It appears that
Greynoiseio
Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
blogs_greynoiseio·2025-01-28·CVSS 8.8
[HIGH] Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter July 2024
blogs_greynoiseio
NoiseLetter July 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2025-02-04
Published
2025-02-11
Added to CISA KEV
Exploited in the wild