A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2024-40891

Zyxel DSL CPE OS Command Injection Vulnerability

Published
2025-02-11
Modified
2026-07-31
Sources
cisa-kev

Summary

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.