CVE-2024-40891
HIGH**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
UNSUPPORTED WHEN ASSIGNED A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
Affected Products
sbg3300-n000 firmwarezyxelsbg3300-nb00 firmwarezyxelsbg3500-n000 firmwarezyxelsbg3500-nb00 firmwarezyxelvmg1312-b10a firmwarezyxelvmg1312-b10b firmwarezyxelFrequently Asked Questions
Is CVE-2024-40891 in your stack?
O3 detects CVE-2024-40891 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.