보안뉴스 아카이브
긴급도 65/100 심각도 미평가 · 미평가 악용확률 97.6% CISA KEV · 2025-02-11

CVE-2024-40890

CISA 기관 조치 기한: 2025-03-04

Zyxel DSL CPE Devices

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
KEV 필수 조치: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

NVD 상세 ↗   참고 링크 ↗

← 취약점 목록