CVE-2024-40891
**UNSUPPORTED WHEN ASSIGNED** Eine Command-Injection-Schwachstelle nach der Authentifizierung in den Management-Befehlen der Legacy-DSL-CPE Zyxel VMG4325-B10A Firmware-Version 1.00(AAFR.4)C0_20170615 könnte es einem authentifizierten Angreifer ermöglichen, Betriebssystembefehle (OS) auf einem betroffenen Gerät über Telnet auszuführen.
Aktiv ausgenutzt
- Seit dem 11. Feb. 2025 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 4. März 2025 beheben (BOD 22-01)
- Angegriffen 7 Tage bevor die Schwachstelle öffentlich wurde
- Durch Sensoren bestätigt, nicht nur durch Meldungen
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Quelle: CISA KEV · 20. Jan. 2026 11. Feb. 2025 28. Jan. 2025
CVSS-Score8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-78
Herstellerzyxel
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| zyxel | vmg1312-b10a firmware | - |
| zyxel | vmg1312-b10a | - |
| zyxel | vmg1312-b10b firmware | - |
| zyxel | vmg1312-b10b | - |
| zyxel | vmg1312-b10e firmware | - |
| zyxel | vmg1312-b10e | - |
| zyxel | vmg3312-b10a firmware | - |
| zyxel | vmg3312-b10a | - |
| zyxel | vmg3313-b10a firmware | - |
| zyxel | vmg3313-b10a | - |
| zyxel | vmg3926-b10b firmware | - |
| zyxel | vmg3926-b10b | - |
| zyxel | vmg4325-b10a firmware | - |
| zyxel | vmg4325-b10a | - |
| zyxel | vmg4380-b10a firmware | - |
| zyxel | vmg4380-b10a | - |
| zyxel | vmg8324-b10a firmware | - |
| zyxel | vmg8324-b10a | - |
| zyxel | vmg8924-b10a firmware | - |
| zyxel | vmg8924-b10a | - |
| zyxel | sbg3300-n000 firmware | - |
| zyxel | sbg3300-n000 | - |
| zyxel | sbg3300-nb00 firmware | - |
| zyxel | sbg3300-nb00 | - |
| zyxel | sbg3500-n000 firmware | - |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
