« Back to list

Zyxel

Zyxel Vmg4380-b10a Firmware: vulnerabilities and CVEs

Zyxel Vmg4380-b10a Firmware has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 2 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical1
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-40890High (8.8)21%⚠ Active exploitationFeb 4, 2025
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated…
CVE-2024-40891High (8.8)22%⚠ Active exploitationFeb 4, 2025
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-0890Critical (9.8)14%—Feb 4, 2025
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management…
CVE-2024-40891High (8.8)22%⚠ Active exploitationFeb 4, 2025
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an…
CVE-2024-40890High (8.8)21%⚠ Active exploitationFeb 4, 2025
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated…
CVE-2015-7256Medium (5.9)0.79%—Sep 28, 2017
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1059 Command and Scripting Interpreter1
  3. T1078 Valid Accounts1
  4. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Zyxel