Exploited Vulnerabilities Daily
🌐 English

Home › Zyxel

CVE-2024-40890: Zyxel DSL CPE Devices

EPSS20.7%No. 1119 of 1739 in KEV
CVE year2024~1 yrs before listing
Same vendor in KEV13
Same product2
FieldValue
VendorZyxel
ProductDSL CPE Devices
NameZyxel DSL CPE OS Command Injection Vulnerability
Added to KEV2025-02-11
US federal due date2025-03-04
Ransomware useUnknown
CWECWE-78

CISA description

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2024-40891Zyxel DSL CPE Devices2025-02-1121.7%Unknown

NVD — CVE-2024-40890

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Zyxel DSL CPE Devices vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-11.