CVE-2024-40891Patch(zyxel / sbg3300-n000)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zyxel sbg3300-n000 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-04. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sbg3300-n000
  • sbg3300-n000_firmware
  • sbg3300-nb00
  • sbg3300-nb00_firmware

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
sbg3300-n000sbg3300-n000_firmwaresbg3300-nb00sbg3300-nb00_firmwaresbg3500-n000_firmwaresbg3500-nb00sbg3500-nb00_firmwarevmg1312-b10avmg1312-b10a_firmwarevmg1312-b10b

1 version affected across 27 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-27: 102-27
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Eclypsium@eclypsium
    Patch

    Organizations using Zyxel products should prioritize installing the recommended patches and consider replacing any legacy devices that are no longer supported or have reached end-of-life status (CVE-2025-13943, CVE-2026-1459, CVE-2024-40891). https://hubs.ly/Q0451tTh0

    Post summary

    Zyxel recommends installing patches for CVE-2025-13943, CVE-2026-1459, and CVE-2024-40891, and advises replacing unsupported legacy devices.

    00000175
    1.8K followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
HWzyxelsbg3300-n000---
OSzyxelsbg3300-n000_firmware---
HWzyxelsbg3300-nb00---
OSzyxelsbg3300-nb00_firmware---
OSzyxelsbg3500-n000_firmware---
HWzyxelsbg3500-nb00---
OSzyxelsbg3500-nb00_firmware---
HWzyxelvmg1312-b10a---
OSzyxelvmg1312-b10a_firmware---
HWzyxelvmg1312-b10b---
OSzyxelvmg1312-b10b_firmware---
HWzyxelvmg1312-b10e---
OSzyxelvmg1312-b10e_firmware---
HWzyxelvmg3312-b10a---
OSzyxelvmg3312-b10a_firmware---
HWzyxelvmg3313-b10a---
OSzyxelvmg3313-b10a_firmware---
HWzyxelvmg3926-b10b---
OSzyxelvmg3926-b10b_firmware---
HWzyxelvmg4325-b10a---
OSzyxelvmg4325-b10a_firmware---
HWzyxelvmg4380-b10a---
OSzyxelvmg4380-b10a_firmware---
HWzyxelvmg8324-b10a---
OSzyxelvmg8324-b10a_firmware---
HWzyxelvmg8924-b10a---
OSzyxelvmg8924-b10a_firmware---

Explore more