HomeSecurityZyxel will not fix two new vulnerabilities in end-of-life devices

Zyxel will not patch two new vulnerabilities in end-of-life devices

Zyxel has issued a new security advisory regarding some vulnerabilities exploited by hackers affecting its CPE series devices, and warned that it does not plan to fix them, as the devices are no longer supported by the company (they have reached end-of-life – EoL). The company urges users to switch to supported models.

Zyxel will not patch two new vulnerabilities in end-of-life devices

VulnCheck discovered the two vulnerabilities in July 2024. However, last week, GreyNoise reported exploitation attempts.

According to network scanning engines FOFA and Censys, more than 1,500 Zyxel CPE series devices are exposed online, meaning they are vulnerable to these attacks.

See also: AMD SEV-SNP vulnerability allows injection of malicious microcode

VulnCheck presented the two Zyxel vulnerabilities, which are used in attacks aimed at gaining initial access to networks:

  • CVE-2024-40891: Privileged users can exploit Telnet command injection due to improper command validation in libcms_cli.so. Certain commands (e.g. ifconfig, ping, tftp) are passed unchecked to a shell execution function, allowing arbitrary code execution with shell metacharacters.
  • CVE-2025-0890: Devices use weak default credentials (admin:1234, zyuser:1234, supervisor:zyad1234), which many users do not change. At the same time, the supervisor account has hidden privileges, providing full access to the system, while zyuser can exploit CVE-2024-40891 for remote code execution.

Researchers warned that these Zyxel devices have been out of support for several years (EoL), but are still in use.

Zyxel recommends replacing the devices

Zyxel confirms that the above vulnerabilities affect multiple products that have reached end of life (EoL). According to the company, these devices should be replaced with newer generation equipmentto keep networks secure.

We have confirmed that the models reported by VulnCheck, VMG1312-B10A, VMG1312-B10B, VMG1312-B10E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300 and SBG3500 are legacy products that have reached their end of life (EOL) for years,” Zyxel’s advisory states.

See also: Microsoft fixes critical vulnerability in Azure AI Face

Zyxel EoL vulnerabilities
Zyxel will not patch new vulnerabilities in end-of-life devices

Therefore, we strongly recommend that users replace them with newer generation products for optimal protection“.

These vulnerabilities have been discovered in end-of-life CPE devices, but they serve as a reminder for all users to regularly assess network infrastructure and address any outdated or unsupported devices. As technology advances, older hardware and software become more vulnerable to cyberattacks. Therefore, it is important for both organizations and individuals to stay up-to-date with the latest security measures and invest in newer, more secure devices to protect their network and sensitive data.

See also: Alibaba Cloud vulnerability allows data upload

Additionally, Zyxel is committed to providing regular security updates for all actively supported devices, ensuring that its customers are protected from any emerging threats. It also offers ongoing support and maintenance services to help users identify potential vulnerabilities and implement necessary security measures.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS