Exploited Vulnerabilities Daily
🌐 English

Home › Zyxel

CVE-2024-40891: Zyxel DSL CPE Devices

EPSS21.7%No. 1108 of 1739 in KEV
CVE year2024~1 yrs before listing
Same vendor in KEV13
Same product2
FieldValue
VendorZyxel
ProductDSL CPE Devices
NameZyxel DSL CPE OS Command Injection Vulnerability
Added to KEV2025-02-11
US federal due date2025-03-04
Ransomware useUnknown
CWECWE-78

CISA description

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2024-40890Zyxel DSL CPE Devices2025-02-1120.7%Unknown

NVD — CVE-2024-40891

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Zyxel DSL CPE Devices vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-11.