CVE-2024-40890
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
04/02/2025
Last modified:
12/02/2025
Description
**UNSUPPORTED WHEN ASSIGNED**<br />
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page