• News/
  • https://www.darkreading.com/endpoint-security/unpatched-zyxel-cpe-zero-day-cyberattackers

Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers

Dark Reading
·
Kristina Beek
·
Published Jan 29, 2025
·
Updated

NEWS BRIEF A command-injection vulnerability in Zyxel CPE Series devices is being targeted by threat actors, and there's no patch available. The bug, tracked as CVE-2024-40891, was first discovered by VulnCheck, a vulnerability intelligence firm, and disclosed to the vendor last July. Half a year later, Zyxel has yet to fix or even mention the vulnerability. If successfully exploited, CVE-2024-40891 could allow threat actors to execute arbitrary commands on infected devices, ultimately potentially leading to system compromise, network infiltration, and data leaks, according to VulnCheck. Researchers at GreyNoise meanwhile have been coordinating with the researchers at VulnCheck regarding exploitation of the vulnerability, and decided to disclose it publicly this week due to the "large number of attacks" they have been observing. They also noted that CVE-2024-40891 is very similar to a known issue tracked as CVE-2024-40890, with the primary difference between the two being one is telnet-based and the other HTTP-based. Both, however, allow unauthenticated attackers to execute arbitrary commands using service accounts, whether in the "supervisor" or "zyuser" roles. The lack of a patch could be a significant issue: Censys is reporting more than 1,500 vulnerable devices online, and it looks like some botnet operators have built exploits for the bug into their code, according to GreyNoise. "After identifying a significant overlap between IPs exploiting CVE-2024-40891 and those clas...

Read full article

Affected Software

2 affected components
Zyxel CPE Series devices
Zyxel CPE Series

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a command-injection vulnerability in Zyxel CPE Series devices that is being actively exploited by cyberattackers.

2

What security implications are discussed?

The article highlights the risks associated with the unpatched vulnerability CVE-2024-40891, which allows attackers to execute command injection attacks on vulnerable devices.

3

What products or software are affected?

The vulnerable products affected by this security issue are Zyxel CPE Series devices.

4

Who discovered the vulnerability?

The vulnerability was first discovered by VulnCheck, a vulnerability intelligence firm.

5

Is there a patch available for the vulnerability?

No, there is currently no patch available for the command-injection vulnerability in Zyxel CPE Series devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203