Evidence dossier

CVE-2024-40891

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version…

Exploited in the wild (CISA KEV since Feb 11, 2025). Zyxel reports CVSS 3.1 8.8. EPSS estimates 21.5% exploit likelihood as of Aug 27, 2026.

78.379.1Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

State
PUBLISHED
Published
Feb 4, 2025
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    Zyxel

    Record text: **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

    Inspect raw assertion
    Field
    container
    Value
    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Zyxel DSL CPE OS Command Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Zyxel DSL CPE OS Command Injection Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 21.54% probability · 97.44th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.215360000000; percentile 0.974360000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Feb 11, 2025 · first observed Jul 19, 2026

Exploit likelihood21.54%

FIRST EPSS · score date Aug 27, 2026 · 97.4th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

Zyxel · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ZyxelOriginal assertion
Record text

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

Inspect raw assertion
Field
container
Value
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Zyxel DSL CPE OS Command Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Zyxel DSL CPE OS Command Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

21.54% probability · 97.44th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.215360000000; percentile 0.974360000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
28Underlying assertions
27Canonical products
14Target assertions
14Constraint assertions

Grouped from 28 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

29 scope groups

Zyxel · source assertedZyxelVMG4325-B10A firmwareDirect source scope
Affected: <= 1.00(AAFR.4)C0_20170615
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "<= 1.00(AAFR.4)C0_20170615"}]
NVD CPE · HARDWAREzyxelsbg3300-n000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3e70c23cdbeb02477c16248b39a38f41245623e8619924501b63314d2e26d52eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    902a735d-2d84-4183-b4b3-fa36ad9f13a5
NVD CPE · OPERATING SYSTEMzyxelsbg3300-n000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-ea4602b0c7797b4686b535508ef79b3d0796b66bf8d28682c9d23fde5c97e17dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    852e8f04-4c28-4904-aa4a-ace4ead6dc31
NVD CPE · HARDWAREzyxelsbg3300-nb00Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ab8c7e0f292d28cd0a6ec70f733da3e69b220ffe1fbebd02dc2302ac8a305db7Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e4658399-1699-4426-acff-bdee20bf1a54
NVD CPE · OPERATING SYSTEMzyxelsbg3300-nb00_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e0ae34861dd0c3054ca2a2ce4fc3e9ee90c80958684118dfedfe92f84dc638bfLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b338ae18-ece4-4b90-a1d5-16f2983464e7
NVD CPE · OPERATING SYSTEMzyxelsbg3500-n000_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bc4b86c-ed2f-406d-bcaa-b970bad248d8
NVD CPE · OPERATING SYSTEMzyxelsbg3500-n000_firmwareEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bc4b86c-ed2f-406d-bcaa-b970bad248d8
NVD CPE · HARDWAREzyxelsbg3500-nb00Environmental constraint · 1 assertions
Version not applicableCanonical identity product-cc5735571d2d2a85a9c9c2df3077e0117e72c64030d4d82f92199a67e4db9c85Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5185679f-9fbc-4b2e-ae79-1471eb56e46a
NVD CPE · OPERATING SYSTEMzyxelsbg3500-nb00_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-0c06c54cb3c1bed32b222c5bdfdbc933015e9f71de90a8d0a0ff258889206aadLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd0dece6-7afc-4e86-9ffe-1215ecf8324d
NVD CPE · HARDWAREzyxelvmg1312-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-dabc386d075ac87404480754d8fa7f3d7c75b0eff068533af9a9f0129287c408Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b6c4a31-3b83-444f-b5f8-1397b43b2211
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-55b53bd07f433c3a4589bacab687f79d4f42f1b90360f5a884cd126e3a85282dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8cc0c61-eb6a-4736-80e3-b69693d4a2b1
NVD CPE · HARDWAREzyxelvmg1312-b10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-1d10c976395ffe8d1add76ffaf857f50ac754533c2575836730ba9012d71ba49Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b193df7-5ee9-4a78-a01e-753463665627
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10b_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-987facc3e99c8b60ce311663cff268c5d8b95ad5716400048ac230886a85adf5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ef1c4a6-0305-4759-8dec-92eb3d2915b1
NVD CPE · HARDWAREzyxelvmg1312-b10eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-562ed1e68929c60843e985e79efaab07ad895a6522bdabd4624c0e85f2c8774bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    155187ea-4a46-4850-b983-bce245d57777
NVD CPE · OPERATING SYSTEMzyxelvmg1312-b10e_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-bc79cee417ec3d2c7b6efc6fafe0a965233d0d364527ea55eba1f8931a3f71c8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2df4827d-405e-4d21-a17e-a201ec6f79f3
NVD CPE · HARDWAREzyxelvmg3312-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b2748dc6c74999e8d615b1e26a25574d2efeb49caef8facd80a2416f0f5e8ae9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffd9df7d-e6e8-4261-8bd7-12a1ae8839bd
NVD CPE · OPERATING SYSTEMzyxelvmg3312-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-a9fe6df505ff5aa2b698381fe7fe7e7aa7eae8077b1e6ceef5fc0ab828aec938Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e7ac711d-503a-48f9-a523-193f29b9db22
NVD CPE · HARDWAREzyxelvmg3313-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-317bebbe4dcb5c3653665d14196e229f6f60465ea154a52630bd48e47995fa45Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46446ae5-ebc1-4e4c-a30f-c610c3eb0975
NVD CPE · OPERATING SYSTEMzyxelvmg3313-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-ba01e830f486a82af701e61f9ae4c86386ef718e9c6f5e63ef24fd970edf20b8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ddec1767-c8d9-495f-b809-fcdb39dcf98b
NVD CPE · HARDWAREzyxelvmg3926-b10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e56cc6c3ef63ec2fe7734b20c130bb9a017016c6b4de6173dcdfa9c65c2a6011Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1daf061-1975-4a5b-8206-1e9836dba1b0
NVD CPE · OPERATING SYSTEMzyxelvmg3926-b10b_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e1355e93d3f64c26bfeaad7da54e7b7a348b14905a482f27f5658a8054d81a09Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7120e86-98dc-4824-bf59-02234501ea29
NVD CPE · HARDWAREzyxelvmg4325-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-110f3f3896cbe1a844bf9c7c4981e04aece948a394dcc2a44a065a65187b9b5eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    135700af-7ec0-4e94-8552-b6f1038de4a8
NVD CPE · OPERATING SYSTEMzyxelvmg4325-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-efc35132a7de2afd1410a7d17fd438efe4fea36254fd7437158a0f558827555eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b88b7a0d-d194-47d1-9d78-682edfc52b52
NVD CPE · HARDWAREzyxelvmg4380-b10aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cc57b63201767dcdba9b6ba5ff9176bdacea8a446df6dff77d4589aff7691250Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ba2bdf-9aca-4f89-b7b7-fd232a6399cd
NVD CPE · OPERATING SYSTEMzyxelvmg4380-b10a_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-52145aed160f0b3c2baf7582175465c2e2d521c8169c548a87c5f24eb3f76039Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4808fdf8-4815-4c4f-afe7-31eade517b31

Affected-product evidence

Accepted scope and product mapping

14 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0c06c54cb3c1bed32b222c5bdfdbc933015e9f71de90a8d0a0ff258889206aad

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
49eb0bf1-a708-4150-a968-a920030eb6aa
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-11a1d8e945e36f2e063f9aeee0983a3ca2ecfff3b527c9806b092970150cc6d7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f8f78639-1d25-4f8c-ba0b-40970c3e083d
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-307b0940f2387d8d45daa4bd6d8faa8960c99b5276350c52c83e3a3c7a360cf9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1d01b75f-f5b5-47b0-8936-67623505ac77
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-52145aed160f0b3c2baf7582175465c2e2d521c8169c548a87c5f24eb3f76039

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
728f645e-b5d4-43a7-82f1-b4ea3dbe0eb6
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-55b53bd07f433c3a4589bacab687f79d4f42f1b90360f5a884cd126e3a85282d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
383eacf3-e4d5-41b9-a9e3-c5d06e1eb65b
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-89228378337bc89010890ab3f5631370a5c6fa6b62d545bfc2ea4363cda125e1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fe812789-16b1-40cd-9b9e-67bade64a79a
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-987facc3e99c8b60ce311663cff268c5d8b95ad5716400048ac230886a85adf5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
86dfa1e3-a7a4-4b66-8bf9-e89933f883aa
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-a9fe6df505ff5aa2b698381fe7fe7e7aa7eae8077b1e6ceef5fc0ab828aec938

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
319f9c08-991b-40b4-b0df-dfdfc92abf2e
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ba01e830f486a82af701e61f9ae4c86386ef718e9c6f5e63ef24fd970edf20b8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
144d11a2-09f4-4505-8c3a-322ad5288085
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-bc79cee417ec3d2c7b6efc6fafe0a965233d0d364527ea55eba1f8931a3f71c8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0743671b-9a4e-4b16-9e05-6c095b956913
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e0ae34861dd0c3054ca2a2ce4fc3e9ee90c80958684118dfedfe92f84dc638bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cdbc77f1-a3e1-473a-9986-e96b283ed5f0
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e1355e93d3f64c26bfeaad7da54e7b7a348b14905a482f27f5658a8054d81a09

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6297ba59-b92c-494b-a0c8-e7fc40af099d
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ea4602b0c7797b4686b535508ef79b3d0796b66bf8d28682c9d23fde5c97e17d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3bb2df4b-ee6c-449b-9974-a39777f5a7fe
Mapping establishedEvidence supported

vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-efc35132a7de2afd1410a7d17fd438efe4fea36254fd7437158a0f558827555e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
77b7ae4e-a8a6-4d8b-bc86-dd529a58264e
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
14eab0b8-8a48-4381-9af8-3024db5d85c3

Assessments

CVSS by origin

8.8
security@zyxel.com.twCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
ZyxelCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

Zyxel

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.