Vulnerability Management

Actively-Exploited Bugs In Zyxel Routers Require Immediate Device Upgrades

Actively-exploited Zyxel bugs require immediate device upgrades. (Zyxel)

Ongoing attacks targeting end-of-life Zyxel CPE Series routers impacted by the CVE-2024-40891 and CVE-2025-0890 vulnerabilities that could be leveraged for code execution have prompted Zyxel to recommend immediate upgrades to newer devices as it warned of no longer addressing the actively exploited bugs, BleepingComputer reports.

Included in the affected CPE Series router models were VMG1312-B10A, VMG1312-B10B, VMG1312-B10E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300, and SBG3500, according to Zyxel, citing reporting from VulnCheck — which identified the flaws in July.

"While these systems are older and seemingly long out of support, they remain highly relevant due to their continued use worldwide and the sustained interest from attackers," said VulnCheck. "The fact that attackers are still actively-exploiting these routers underscores the need for attention, as understanding real-world attacks is critical to effective security research."

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.