Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel · DSL CPE Devices
CVSS 8.8
EPSS 22%
no public exploit indexed
Fix deadline passed 4 March 2025
What it is
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Why we say that
- CISA's federal remediation deadline (2025-03-04) has passed
- Listed in the CISA Known Exploited Vulnerabilities catalogue
Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.
What to do
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
What it costs when this goes wrong
This is where UK enforcement meets the vulnerability record. Where an unfixed vulnerability leads to a breach, the ICO treats it as a security failure under UK GDPR. Recent cases:
- The Electoral Commission Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 20…
- Gain Capital UK Limited Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged a…
- Chartered Institute for Securities & Investment An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a…