Evidence dossier

CVE-2024-40890

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version…

Exploited in the wild (CISA KEV since Feb 11, 2025). Zyxel reports CVSS 3.1 8.8. EPSS estimates 22.3% exploit likelihood as of Aug 27, 2026.

78.479.2Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

State
PUBLISHED
Published
Feb 4, 2025
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    Zyxel

    Record text: **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

    Inspect raw assertion
    Field
    container
    Value
    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Zyxel DSL CPE OS Command Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Zyxel DSL CPE OS Command Injection Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 22.25% probability · 97.5th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.222510000000; percentile 0.975010000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Feb 11, 2025 · first observed Jul 19, 2026

Exploit likelihood22.25%

FIRST EPSS · score date Aug 27, 2026 · 97.5th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

Zyxel · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ZyxelOriginal assertion
Record text

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.

Inspect raw assertion
Field
container
Value
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Zyxel DSL CPE OS Command Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Zyxel DSL CPE OS Command Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

22.25% probability · 97.5th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.222510000000; percentile 0.975010000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
28Underlying assertions
27Canonical products
14Target assertions
14Constraint assertions

Grouped from 28 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

29 scope groups

Zyxel · source assertedZyxelVMG4325-B10A firmwareDirect source scope
Affected: <= 1.00(AAFR.4)C0_20170615
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "<= 1.00(AAFR.4)C0_20170615"}]
NVD CPE · HARDWAREzyxelsbg3300-n000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3e70c23cdbeb02477c16248b39a38f41245623e8619924501b63314d2e26d52eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    902a735d-2d84-4183-b4b3-fa36ad9f13a5
NVD CPE · OPERATING SYSTEMzyxelsbg3300-n000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-ea4602b0c7797b4686b535508ef79b3d0796b66bf8d28682c9d23fde5c97e17dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    852e8f04-4c28-4904-aa4a-ace4ead6dc31
NVD CPE · HARDWAREzyxelsbg3300-nb00Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ab8c7e0f292d28cd0a6ec70f733da3e69b220ffe1fbebd02dc2302ac8a305db7Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e4658399-1699-4426-acff-bdee20bf1a54
NVD CPE · OPERATING SYSTEMzyxelsbg3300-nb00_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e0ae34861dd0c3054ca2a2ce4fc3e9ee90c80958684118dfedfe92f84dc638bfLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b338ae18-ece4-4b90-a1d5-16f2983464e7
NVD CPE · OPERATING SYSTEMzyxelsbg3500-n000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bc4b86c-ed2f-406d-bcaa-b970bad248d8
NVD CPE · OPERATING SYSTEMzyxelsbg3500-n000_firmwareEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bc4b86c-ed2f-406d-bcaa-b970bad248d8
NVD CPE · HARDWAREzyxelsbg3500-nb00Environmental constraint · 1 assertions
Version not applicableCanonical identity product-cc5735571d2d2a85a9c9c2df3077e0117e72c64030d4d82f92199a67e4db9c85Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5185679f-9fbc-4b2e-ae79-1471eb56e46a
NVD CPE · OPERATING SYSTEMzyxelsbg3500-nb00_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-0c06c54cb3c1bed32b222c5bdfdbc933015e9f71de90a8d0a0ff258889206aadLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd0dece6-7afc-4e86-9ffe-1215ecf8324d
NVD CPE · HARDWAREzyxelvmg1312-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-dabc386d075ac87404480754d8fa7f3d7c75b0eff068533af9a9f0129287c408Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b6c4a31-3b83-444f-b5f8-1397b43b2211
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-55b53bd07f433c3a4589bacab687f79d4f42f1b90360f5a884cd126e3a85282dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8cc0c61-eb6a-4736-80e3-b69693d4a2b1
NVD CPE · HARDWAREzyxelvmg1312-b10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-1d10c976395ffe8d1add76ffaf857f50ac754533c2575836730ba9012d71ba49Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b193df7-5ee9-4a78-a01e-753463665627
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10b_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-987facc3e99c8b60ce311663cff268c5d8b95ad5716400048ac230886a85adf5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ef1c4a6-0305-4759-8dec-92eb3d2915b1
NVD CPE · HARDWAREzyxelvmg1312-b10eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-562ed1e68929c60843e985e79efaab07ad895a6522bdabd4624c0e85f2c8774bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    155187ea-4a46-4850-b983-bce245d57777
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10e_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-bc79cee417ec3d2c7b6efc6fafe0a965233d0d364527ea55eba1f8931a3f71c8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2df4827d-405e-4d21-a17e-a201ec6f79f3
NVD CPE · HARDWAREzyxelvmg3312-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b2748dc6c74999e8d615b1e26a25574d2efeb49caef8facd80a2416f0f5e8ae9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffd9df7d-e6e8-4261-8bd7-12a1ae8839bd
NVD CPE · OPERATING SYSTEMzyxelvmg3312-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-a9fe6df505ff5aa2b698381fe7fe7e7aa7eae8077b1e6ceef5fc0ab828aec938Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e7ac711d-503a-48f9-a523-193f29b9db22
NVD CPE · HARDWAREzyxelvmg3313-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-317bebbe4dcb5c3653665d14196e229f6f60465ea154a52630bd48e47995fa45Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46446ae5-ebc1-4e4c-a30f-c610c3eb0975
NVD CPE · OPERATING SYSTEMzyxelvmg3313-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-ba01e830f486a82af701e61f9ae4c86386ef718e9c6f5e63ef24fd970edf20b8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ddec1767-c8d9-495f-b809-fcdb39dcf98b
NVD CPE · HARDWAREzyxelvmg3926-b10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e56cc6c3ef63ec2fe7734b20c130bb9a017016c6b4de6173dcdfa9c65c2a6011Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1daf061-1975-4a5b-8206-1e9836dba1b0
NVD CPE · OPERATING SYSTEMzyxelvmg3926-b10b_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e1355e93d3f64c26bfeaad7da54e7b7a348b14905a482f27f5658a8054d81a09Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7120e86-98dc-4824-bf59-02234501ea29
NVD CPE · HARDWAREzyxelvmg4325-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-110f3f3896cbe1a844bf9c7c4981e04aece948a394dcc2a44a065a65187b9b5eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    135700af-7ec0-4e94-8552-b6f1038de4a8
NVD CPE · OPERATING SYSTEMzyxelvmg4325-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-efc35132a7de2afd1410a7d17fd438efe4fea36254fd7437158a0f558827555eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b88b7a0d-d194-47d1-9d78-682edfc52b52
NVD CPE · HARDWAREzyxelvmg4380-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cc57b63201767dcdba9b6ba5ff9176bdacea8a446df6dff77d4589aff7691250Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ba2bdf-9aca-4f89-b7b7-fd232a6399cd
NVD CPE · OPERATING SYSTEMzyxelvmg4380-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-52145aed160f0b3c2baf7582175465c2e2d521c8169c548a87c5f24eb3f76039Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4808fdf8-4815-4c4f-afe7-31eade517b31

Affected-product evidence

Accepted scope and product mapping

14 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0c06c54cb3c1bed32b222c5bdfdbc933015e9f71de90a8d0a0ff258889206aad

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
61e78686-909b-4061-9185-d9e7d2c0c57f
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-11a1d8e945e36f2e063f9aeee0983a3ca2ecfff3b527c9806b092970150cc6d7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3d922536-ddde-4971-9a11-fa068111385a
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-307b0940f2387d8d45daa4bd6d8faa8960c99b5276350c52c83e3a3c7a360cf9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
efcbbd46-b9df-4447-ad72-ea88439196ec
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-52145aed160f0b3c2baf7582175465c2e2d521c8169c548a87c5f24eb3f76039

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f1f22e81-0681-4345-a875-03caad672b40
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-55b53bd07f433c3a4589bacab687f79d4f42f1b90360f5a884cd126e3a85282d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d948e5fc-5bac-4e99-8d0c-af173fdbcad6
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f493b0a2-57b1-4288-93ba-94936f89587f
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-987facc3e99c8b60ce311663cff268c5d8b95ad5716400048ac230886a85adf5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
14fd9011-b0d7-45e2-a711-9c120a355a0a
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-a9fe6df505ff5aa2b698381fe7fe7e7aa7eae8077b1e6ceef5fc0ab828aec938

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2a69b036-96d5-43f3-847f-2ca7f7527645
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ba01e830f486a82af701e61f9ae4c86386ef718e9c6f5e63ef24fd970edf20b8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5309e333-a831-4df0-a4d8-79ab03efce34
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-bc79cee417ec3d2c7b6efc6fafe0a965233d0d364527ea55eba1f8931a3f71c8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
938caa8d-dc5c-4627-a244-281d9818eaff
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e0ae34861dd0c3054ca2a2ce4fc3e9ee90c80958684118dfedfe92f84dc638bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3a4c2b03-322f-4998-9da5-8e7b88687c12
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e1355e93d3f64c26bfeaad7da54e7b7a348b14905a482f27f5658a8054d81a09

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
78e72e2e-c06f-4102-b469-d83f8c5074ce
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ea4602b0c7797b4686b535508ef79b3d0796b66bf8d28682c9d23fde5c97e17d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0405a359-ead4-416b-96ee-de0d067a24f5
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-efc35132a7de2afd1410a7d17fd438efe4fea36254fd7437158a0f558827555e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
08201ffb-59f9-4cad-886f-d56ae8688952
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
23fdc4cf-4f15-470e-9bab-df93e048a06d

Assessments

CVSS by origin

8.8
security@zyxel.com.twCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
ZyxelCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

Zyxel

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.