Description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

INFO

Published Date :

2025-02-04T09:55:38.908Z

Last Modified :

2025-10-21T22:55:30.414Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2024-40890 vulnerability.

Vendors Products
Zyxel
  • Sbg3300-n000
  • Sbg3300-n000 Firmware
  • Sbg3300-nb00
  • Sbg3300-nb00 Firmware
  • Sbg3500-n000 Firmware
  • Sbg3500-nb00
  • Sbg3500-nb00 Firmware
  • Vmg1312-b10a
  • Vmg1312-b10a Firmware
  • Vmg1312-b10b
  • Vmg1312-b10b Firmware
  • Vmg1312-b10e
  • Vmg1312-b10e Firmware
  • Vmg3312-b10a
  • Vmg3312-b10a Firmware
  • Vmg3313-b10a
  • Vmg3313-b10a Firmware
  • Vmg3926-b10b
  • Vmg3926-b10b Firmware
  • Vmg4325-b10a
  • Vmg4325-b10a Firmware
  • Vmg4380-b10a
  • Vmg4380-b10a Firmware
  • Vmg8324-b10a
  • Vmg8324-b10a Firmware
  • Vmg8924-b10a
  • Vmg8924-b10a Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact