As cited
Copy frozen at (site build).
vulnerabilities
Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
A telnet-based command injection vulnerability (CVE-2024-40891) in Zyxel Customer Premises Equipment (CPE) devices is being actively exploited in the wild. Over 1,500 exposed systems are currently at risk, and the vendor has not yet released a patch.
Why it matters: Organizations running Zyxel CPE devices need to immediately inventory and isolate affected systems, as attackers are actively exploiting this vulnerability and a vendor patch is unavailable.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
A telnet-based command injection vulnerability (CVE-2024-40891) in Zyxel Customer Premises Equipment (CPE) devices is being actively exploited in the wild. Over 1,500 exposed systems are currently at risk, and the vendor has not yet released a patch.
Why it matters: Organizations running Zyxel CPE devices need to immediately inventory and isolate affected systems, as attackers are actively exploiting this vulnerability and a vendor patch is unavailable.
- Source published
- First seen by Cybersecurity Tracker