Zyxel Zero-Day Chaos: No Patch, No Peace!

GreyNoise reports a zero-day vulnerability in Zyxel CPE devices with no vendor patches in sight. This critical command injection flaw, CVE-2024-40891, exposes over 1,500 devices to potential system compromise. As Zyxel remains silent, GreyNoise urges immediate security measures to mitigate risks.

Pro Dashboard

Hot Take:

Looks like Zyxel devices are throwing a zero-day vulnerability party, and everyone’s invited—except the patches. With Telnet as the bouncer, it’s open season for cyber attackers, so grab your popcorn as we watch this cybersecurity thriller unfold without an intermission from Zyxel.

Key Points:

  • GreyNoise discovers zero-day vulnerability in Zyxel CPE devices with no patches available.
  • The flaw allows for full system compromise via Telnet command injection.
  • Over 1,500 devices are currently vulnerable, according to Censys data.
  • Vulnerability is similar to a previously patched issue but uses a different attack vector.
  • GreyNoise recommends immediate defensive actions due to lack of vendor communication.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?