A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel sbg3300-n000 Zyxel sbg3300-n000 Firmware Zyxel sbg3300-nb00 Zyxel sbg3300-nb00 Firmware Zyxel sbg3500-n000 Firmware Zyxel sbg3500-nb00 Zyxel sbg3500-nb00 Firmware Zyxel vmg1312-b10a Zyxel vmg1312-b10a Firmware Zyxel vmg1312-b10b Zyxel vmg1312-b10b Firmware Zyxel vmg1312-b10e Zyxel vmg1312-b10e Firmware Zyxel vmg3312-b10a Zyxel vmg3312-b10a Firmware Zyxel vmg3313-b10a Zyxel vmg3313-b10a Firmware Zyxel vmg3926-b10b Zyxel vmg3926-b10b Firmware Zyxel vmg4325-b10a Zyxel vmg4325-b10a Firmware Zyxel vmg4380-b10a Zyxel vmg4380-b10a Firmware Zyxel vmg8324-b10a Zyxel vmg8324-b10a Firmware Zyxel vmg8924-b10a Zyxel vmg8924-b10a Firmware |
|
| CPEs | cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel
Zyxel sbg3300-n000 Zyxel sbg3300-n000 Firmware Zyxel sbg3300-nb00 Zyxel sbg3300-nb00 Firmware Zyxel sbg3500-n000 Firmware Zyxel sbg3500-nb00 Zyxel sbg3500-nb00 Firmware Zyxel vmg1312-b10a Zyxel vmg1312-b10a Firmware Zyxel vmg1312-b10b Zyxel vmg1312-b10b Firmware Zyxel vmg1312-b10e Zyxel vmg1312-b10e Firmware Zyxel vmg3312-b10a Zyxel vmg3312-b10a Firmware Zyxel vmg3313-b10a Zyxel vmg3313-b10a Firmware Zyxel vmg3926-b10b Zyxel vmg3926-b10b Firmware Zyxel vmg4325-b10a Zyxel vmg4325-b10a Firmware Zyxel vmg4380-b10a Zyxel vmg4380-b10a Firmware Zyxel vmg8324-b10a Zyxel vmg8324-b10a Firmware Zyxel vmg8924-b10a Zyxel vmg8924-b10a Firmware |
Wed, 12 Feb 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Tue, 11 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2025-10-21T22:55:30.272Z
Reserved: 2024-07-11T17:35:29.595Z
Link: CVE-2024-40891
Updated: 2025-02-11T19:02:56.761Z
Status : Analyzed
Published: 2025-02-04T10:15:08.920
Modified: 2025-10-27T17:04:37.300
Link: CVE-2024-40891
No data.
OpenCVE Enrichment
No data.