Zyxel Zero-Day Chaos: No Patch, No Peace!
GreyNoise reports a zero-day vulnerability in Zyxel CPE devices with no vendor patches in sight. This critical command injection flaw, CVE-2024-40891, exposes over 1,500 devices to potential system compromise. As Zyxel remains silent, GreyNoise urges immediate security measures to mitigate risks.

Hot Take:
Looks like Zyxel devices are throwing a zero-day vulnerability party, and everyone’s invited—except the patches. With Telnet as the bouncer, it’s open season for cyber attackers, so grab your popcorn as we watch this cybersecurity thriller unfold without an intermission from Zyxel.
Key Points:
- GreyNoise discovers zero-day vulnerability in Zyxel CPE devices with no patches available.
- The flaw allows for full system compromise via Telnet command injection.
- Over 1,500 devices are currently vulnerable, according to Censys data.
- Vulnerability is similar to a previously patched issue but uses a different attack vector.
- GreyNoise recommends immediate defensive actions due to lack of vendor communication.
Already a member? Log in here