Zyxel has issued a new security advisory regarding some vulnerabilities exploited by hackers affecting its CPE series devices, and warned that it does not plan to fix them, as the devices are no longer supported by the company (they have reached end-of-life – EoL). The company urges users to switch to supported models.

VulnCheck discovered the two vulnerabilities in July 2024. However, last week, GreyNoise reported exploitation attempts.
According to network scanning engines FOFA and Censys, more than 1,500 Zyxel CPE series devices are exposed online, meaning they are vulnerable to these attacks.
See also: AMD SEV-SNP vulnerability allows injection of malicious microcode
VulnCheck presented the two Zyxel vulnerabilities, which are used in attacks aimed at gaining initial access to networks:
- CVE-2024-40891: Privileged users can exploit Telnet command injection due to improper command validation in libcms_cli.so. Certain commands (e.g. ifconfig, ping, tftp) are passed unchecked to a shell execution function, allowing arbitrary code execution with shell metacharacters.
- CVE-2025-0890: Devices use weak default credentials (admin:1234, zyuser:1234, supervisor:zyad1234), which many users do not change. At the same time, the supervisor account has hidden privileges, providing full access to the system, while zyuser can exploit CVE-2024-40891 for remote code execution.
Researchers warned that these Zyxel devices have been out of support for several years (EoL), but are still in use.
Zyxel recommends replacing the devices
Zyxel confirms that the above vulnerabilities affect multiple products that have reached end of life (EoL). According to the company, these devices should be replaced with newer generation equipmentto keep networks secure.
“We have confirmed that the models reported by VulnCheck, VMG1312-B10A, VMG1312-B10B, VMG1312-B10E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300 and SBG3500 are legacy products that have reached their end of life (EOL) for years,” Zyxel’s advisory states.
See also: Microsoft fixes critical vulnerability in Azure AI Face

“Therefore, we strongly recommend that users replace them with newer generation products for optimal protection“.
These vulnerabilities have been discovered in end-of-life CPE devices, but they serve as a reminder for all users to regularly assess network infrastructure and address any outdated or unsupported devices. As technology advances, older hardware and software become more vulnerable to cyberattacks. Therefore, it is important for both organizations and individuals to stay up-to-date with the latest security measures and invest in newer, more secure devices to protect their network and sensitive data.
See also: Alibaba Cloud vulnerability allows data upload
Additionally, Zyxel is committed to providing regular security updates for all actively supported devices, ensuring that its customers are protected from any emerging threats. It also offers ongoing support and maintenance services to help users identify potential vulnerabilities and implement necessary security measures.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
