logo

Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers

ID: 6dcfde09-a418-5344-8012-d58b9abb2ea3

STIX ID: report--6dcfde09-a418-5344-8012-d58b9abb2ea3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-29

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A command-injection zero-day (CVE-2024-40891) affecting Zyxel CPE devices is being actively exploited and remains unpatched; researchers from VulnCheck and GreyNoise observed widespread exploitation and noted Mirai variants have integrated the exploit, with over 1,500 vulnerable devices exposed online, prompting urgent network filtering and access-restriction mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.