Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers
ID: 6dcfde09-a418-5344-8012-d58b9abb2ea3
STIX ID: report--6dcfde09-a418-5344-8012-d58b9abb2ea3
Feed Name: Dark Reading
Threat Score
Date Published: 2025-01-29
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
...
...
A command-injection zero-day (CVE-2024-40891) affecting Zyxel CPE devices is being actively exploited and remains unpatched; researchers from VulnCheck and GreyNoise observed widespread exploitation and noted Mirai variants have integrated the exploit, with over 1,500 vulnerable devices exposed online, prompting urgent network filtering and access-restriction mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
