CVE-2024-40890

**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ZyxelCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
zyxelvmg1312-b10a_firmware
-
zyxelvmg1312-b10b_firmware
-
zyxelvmg1312-b10e_firmware
-
zyxelvmg3312-b10a_firmware
-
zyxelvmg3313-b10a_firmware
-
zyxelvmg3926-b10b_firmware
-
zyxelvmg4325-b10a_firmware
-
zyxelvmg4380-b10a_firmware
-
zyxelvmg8324-b10a_firmware
-
zyxelvmg8924-b10a_firmware
-
zyxelsbg3300-n000_firmware
-
zyxelsbg3300-nb00_firmware
-
zyxelsbg3500-n000_firmware
-
zyxelsbg3500-nb00_firmware
-
𝑥
= Vulnerable software versions