Researchers and defenders warned that two critical zero-day vulnerabilities in Zyxel CPE devices, CVE-2024-40890 and CVE-2024-40891, are being actively exploited in the wild. The flaws affect Zyxel CPE models that are now end-of-life and can enable command injection leading to full device compromise; reporting from GreyNoise highlighted active exploitation of CVE-2024-40891, while CSIRT.SK said Mirai-based botnet variants have been observed abusing the issue.
The exposed devices appear to be attractive initial-access targets because they sit at the network edge and can be conscripted into botnets or used as footholds into victim environments. Zyxel is not expected to issue patches for the affected hardware, leaving organizations to mitigate by replacing vulnerable devices, restricting access to administrative interfaces, and increasing monitoring of HTTP and Telnet traffic for signs of exploitation and post-compromise activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In its advisory, CSIRT.SK stated that the affected Zyxel CPE models were end-of-life and that Zyxel was not expected to release patches. It recommended replacing vulnerable devices, restricting administrative interface access, and monitoring HTTP and Telnet traffic.
CSIRT.SK warned that both CVE-2024-40890 and CVE-2024-40891 in Zyxel CPE devices were under active exploitation. It said the flaws could enable command injection and full compromise, and noted reports linking CVE-2024-40891 exploitation to Mirai-based botnet variants.
GreyNoise reported that the Zyxel CPE vulnerability CVE-2024-40891 was being actively exploited as a zero-day. The report tied exploitation to internet-exposed Zyxel devices.
VulnCheck's July 2024 Initial Access Intelligence update included CVE-2024-40891 among notable vulnerabilities, establishing early public tracking of the Zyxel CPE issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcegreynoise.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.