Evidence dossier

CVE-2024-40890

CVE-2024-40890

71.586.5Priority evidence range
As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9

Normalized restatement

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

State
PUBLISHED
Published
Feb 4, 2025
Updated
Oct 21, 2025
Evidence coverage
85%
CISA KEVCatalog member

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

FIRST EPSS22.42%

2026-07-18 · v2026.06.15 · percentile 97.4%

Source stateNo scored conflict

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

Zyxeloriginal assertion
container

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

CISA KEVoriginal assertion
observed_exploitation

Zyxel DSL CPE OS Command Injection Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.224210000000; percentile 0.974310000000

Applicability

Cited product scope

Trace impact →
ZyxelVMG4325-B10A firmware
[{"status": "affected", "version": "<= 1.00(AAFR.4)C0_20170615"}]unknown
Unknown vendorUnknown product
cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*constrained
Unknown vendorUnknown product
cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:*supported

Assessments

CVSS by origin

8.8
security@zyxel.com.twCVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
ZyxelCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.