CVE-2024-40891
published 2025-02-04CVE-2024-40891: **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A…
PriorityP189high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-03-04
Exploited in the wild
EPSS
19.73%
97.1th percentile
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | vmg4325-b10a_firmware | <= 1.00(AAFR.4)C0_20170615 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel runCommandInShell Telnet Service Command Injection Attempt (CVE-2024-40891)"; flow:established,to_server; app-layer-protocol:telnet; pcre:"/^.*(?:cat|ifconfig|ping|ps|pwd|tftp|wlctl).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26|%26))*?sh/"; content:"sh"; fast_pattern; reference:cve,2024-40891; reference:url,vulncheck.com/blog/zyxel-telnet-vulns; classtype:attempted-admin; sid:2060323; rev:2; metadata:affected_product Zyxel, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_02_24, cve CVE_2024_40891, deployment Perimeter, deployment Internal, performance_impact Moderate, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2025_03_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
- →Monitor for Telnet (TCP/23) traffic to Zyxel CPE management interfaces containing shell metacharacters (;, newline, backtick, |, $, &) appended to known injectable commands (cat, ifconfig, ping, ps, pwd, tftp, wlctl) followed by 'sh'.
- →Exploitation leverages service accounts 'supervisor' and/or 'zyuser' over Telnet; alert on Telnet authentication using these usernames. ↗
- →Weak default credentials used in exploitation: admin:1234, zyuser:1234, supervisor:zyad1234. Alert on Telnet login attempts using these credential pairs against Zyxel CPE devices. ↗
- →Significant overlap observed between IPs exploiting CVE-2024-40891 and Mirai botnet IPs; correlate exploitation attempts with known Mirai infrastructure. ↗
- →The vulnerable code path is in libcms_cli.so; on-device forensics should look for unexpected execution chains originating from this library. ↗
- ·The vulnerability affects only legacy/EoL firmware; the specific confirmed vulnerable firmware version is 1.00(AAFR.4)C0_20170615 on VMG4325-B10A. Zyxel has confirmed no patch will be issued. ↗
- ·Exploitation is post-authentication via Telnet, but CVE-2025-0890 (default credentials) effectively makes this pre-auth in practice for devices with unchanged defaults. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pm4h-579g-cgqq: **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10
ghsa_unreviewed·2025-02-04
CVE-2024-40891 [HIGH] CWE-78 GHSA-pm4h-579g-cgqq: **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
VulnCheck
Zyxel DSL CPE OS Command Injection Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-40890 [HIGH] CWE-78 Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Affected: Zyxel DSL CPE Devices
Required Action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Exploitation References: https://www.greynoise.io/blog/active-exploitation-of-zero-day-zyxel-cpe-vulnerability-cve-2024-40891; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Remediation Due: 2025-03-04
VulnCheck
Zyxel DSL CPE OS Command Injection Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-40891 [HIGH] CWE-78 Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Affected: Zyxel DSL CPE Devices
Required Action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Exploitation References: https://www.greynoise.io/blog/active-exploitation-of-zero-day-zyxel-cpe-vulnerability-cve-2024-40891; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Remediation Due: 2025-03-04
CISA
Zyxel DSL CPE OS Command Injection Vulnerability
cisa·2025-02-11·CVSS 8.8
CVE-2024-40891 [HIGH] CWE-78 Zyxel DSL CPE OS Command Injection Vulnerability
Vulnerability: Zyxel DSL CPE OS Command Injection Vulnerability
Affected: Zyxel DSL CPE Devices
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Required Action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 ; https://www.zyxel.com/service-provider/global/en/security-advisories/zyxel-security-advisory-command-injection-insecure-in-
Suricata
ET EXPLOIT Zyxel runCommandInShell Telnet Service Command Injection Attempt (CVE-2024-40891)
suricata·2025-02-24·CVSS 8.8
CVE-2024-40891 [HIGH] ET EXPLOIT Zyxel runCommandInShell Telnet Service Command Injection Attempt (CVE-2024-40891)
ET EXPLOIT Zyxel runCommandInShell Telnet Service Command Injection Attempt (CVE-2024-40891)
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel runCommandInShell Telnet Service Command Injection Attempt (CVE-2024-40891)"; flow:established,to_server; app-layer-protocol:telnet; pcre:"/^.*(?:cat|ifconfig|ping|ps|pwd|tftp|wlctl).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26|%26))*?sh/"; content:"sh"; fast_pattern; reference:cve,2024-40891; reference:url,vulncheck.com/blog/zyxel-telnet-vulns; classtype:attempted-admin; sid:2060323; rev:2; metadata:affected_product Zyxel, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_02_24, cve CVE_2024_40891, deployment Perimeter, deployment Internal, performance_impact Moderate, c
No public exploits indexed.
Bleepingcomputer
Zyxel warns of critical RCE flaw affecting over a dozen routers
blogs_bleepingcomputer·2026-02-25·CVSS 9.8
CVE-2025-13942 [CRITICAL] Zyxel warns of critical RCE flaw affecting over a dozen routers
## Zyxel warns of critical RCE flaw affecting over a dozen routers
## Sergiu Gatlan
Taiwan networking provider Zyxel has released security updates to address a critical vulnerability affecting over a dozen router models that can allow unauthenticated attackers to gain remote command execution on unpatched devices.
Tracked as CVE-2025-13942, this command injection security flaw was found in the UPnP function of Zyxel 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders.
Zyxel says that unauthenticated remote attackers can exploit it to execute operating system (OS) commands on an affected device using maliciously crafted UPnP SOAP requests.
However, CVE-2025-13942 attacks will likely be more limited than the severity rating suggests, as successful exploitation require
Bleepingcomputer
Zyxel won’t patch newly exploited flaws in end-of-life routers
blogs_bleepingcomputer·2025-02-04·CVSS 8.8
CVE-2024-40891 [HIGH] Zyxel won’t patch newly exploited flaws in end-of-life routers
## Zyxel won’t patch newly exploited flaws in end-of-life routers
## Bill Toulas
In a new post today, VulnCheck presented the full details of the two flaws it observed in attacks aimed at gaining initial access to networks:
CVE-2024-40891 – Authenticated users can exploit Telnet command injection due to improper command validation in libcms_cli.so. Certain commands (e.g., ifconfig, ping, tftp) are passed unchecked to a shell execution function, allowing arbitrary code execution using shell metacharacters.
CVE-2025-0890 – Devices use weak default credentials (admin:1234, zyuser:1234, supervisor:zyad1234), which many users don't change. The supervisor account has hidden privileges, granting full system access, while zyuser can exploit CVE-2024-40891 for remote code execution.
VulnCheck
Bleepingcomputer
Hackers exploit critical unpatched flaw in Zyxel CPE devices
blogs_bleepingcomputer·2025-01-29·CVSS 8.8
CVE-2024-40891 [HIGH] Hackers exploit critical unpatched flaw in Zyxel CPE devices
## Hackers exploit critical unpatched flaw in Zyxel CPE devices
## Bill Toulas
Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July.
The vulnerability allows unauthenticated attackers to execute arbitrary commands using the ‘supervisor’ or ‘zyuser’ service accounts.
Vulnerability intelligence company VulnCheck added the security issue to its database last year on July 12 and listed it among other issues exploited in the wild for initial access.
Technical details on the vulnerability have not been publicly disclosed and Zyxel did not release a security advisory or a patch for CVE-2024-40891, and the issue remains exploitable in the latest firmware.
It appears that
Greynoiseio
Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
blogs_greynoiseio·2025-01-28·CVSS 8.8
[HIGH] Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter January 2025
blogs_greynoiseio
NoiseLetter January 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2025-02-04
Published
2025-02-11
Added to CISA KEV
Exploited in the wild