NEWS BRIEF A command-injection vulnerability in Zyxel CPE Series devices is being targeted by threat actors, and there's no patch available. The bug, tracked as CVE-2024-40891, was first discovered by VulnCheck, a vulnerability intelligence firm, and disclosed to the vendor last July. Half a year later, Zyxel has yet to fix or even mention the vulnerability. If successfully exploited, CVE-2024-40891 could allow threat actors to execute arbitrary commands on infected devices, ultimately potentially leading to system compromise, network infiltration, and data leaks, according to VulnCheck. Researchers at GreyNoise meanwhile have been coordinating with the researchers at VulnCheck regarding exploitation of the vulnerability, and decided to disclose it publicly this week due to the "large number of attacks" they have been observing. They also noted that CVE-2024-40891 is very similar to a known issue tracked as CVE-2024-40890, with the primary difference between the two being one is telnet-based and the other HTTP-based. Both, however, allow unauthenticated attackers to execute arbitrary commands using service accounts, whether in the "supervisor" or "zyuser" roles. The lack of a patch could be a significant issue: Censys is reporting more than 1,500 vulnerable devices online, and it looks like some botnet operators have built exploits for the bug into their code, according to GreyNoise. "After identifying a significant overlap between IPs exploiting CVE-2024-40891 and those clas...
Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers
Dark Reading
·Kristina Beek
·Published Jan 29, 2025
·Updated
Affected Software
2 affected components
Zyxel CPE Series devices
Zyxel CPE Series
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a command-injection vulnerability in Zyxel CPE Series devices that is being actively exploited by cyberattackers.
2
What security implications are discussed?
The article highlights the risks associated with the unpatched vulnerability CVE-2024-40891, which allows attackers to execute command injection attacks on vulnerable devices.
3
What products or software are affected?
The vulnerable products affected by this security issue are Zyxel CPE Series devices.
4
Who discovered the vulnerability?
The vulnerability was first discovered by VulnCheck, a vulnerability intelligence firm.
5
Is there a patch available for the vulnerability?
No, there is currently no patch available for the command-injection vulnerability in Zyxel CPE Series devices.