The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Evidence dossier
CVE-2024-40891
CVE-2024-40891
gen-56ccdaf9Normalized restatement
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
- State
- PUBLISHED
- Published
- Feb 4, 2025
- Updated
- Oct 21, 2025
- Evidence coverage
- 85%
2026-07-18 · v2026.06.15 · percentile 97.4%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
Zyxel DSL CPE OS Command Injection Vulnerability
Probability 0.219960000000; percentile 0.973930000000
Applicability
Cited product scope
[{"status": "affected", "version": "<= 1.00(AAFR.4)C0_20170615"}]unknowncpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:*constrainedcpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*constrainedcpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:*supportedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.