Skip to content
COOEY

FAIL › dossier

DSL CPE Devices

PRODUCT

· dossier confidence 90%

DSL CPE devices suffer from critically exploited command injection vulnerabilities, with active RCE exploits in the wild indicating a severe failure to patch edge devices against known threats.

PROFILE
CategoryDSL CPE DevicesWhat they doDSL CPE devices are customer premises equipment used for DSL internet connectivity.
SECURITY POSTURE

The security posture is critically compromised by active exploitation of high-severity command injection vulnerabilities in the wild, indicating a failure to patch or secure edge devices against known exploits.

Notable failures
  • CVE-2024-40890: Active exploitation of authenticated command injection RCE
  • CVE-2024-40891: Remote command injection via Telnet after authentication
Patterns: Repeated unpatched command injection vulnerabilities in edge devices; Active exploitation of high-severity CVEs in the wild
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-02-11 CVE-2024-40890 high Zyxel DSL CPE devices have a command injection vulnerability actively exploited in the wild, allowing authenticated attackers to execute OS commands.
2025-02-11 CVE-2024-40891 high Zyxel DSL CPE devices have a command injection vulnerability exploitable via Telnet after authentication, allowing attackers to execute OS commands remotely.
Open questions: Are there additional unpatched vulnerabilities in Zyxel DSL CPE devices? · What is the current patch status for CVE-2024-40890 and CVE-2024-40891?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:29:10.398170+00:00