RaqibCTI
CVE

CVE-2024-40891

P2
Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel · DSL CPE Devices
Date added (CISA)
2025-02-11
Remediation due
2025-03-04
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

Source: NVD ↗ · CISA KEV Catalog ↗