Zyxel’s CPE devices are vulnerable to active exploitation due to the CVE-2024-40891 vulnerability that has not been patched.
Cybersecurity researchers warn that Zyxel CPE Series device users are actively attempting to exploit a critical zero day vulnerability. GreyNoise researcher Glenn Thorpe stated in an alert that “Attackers could leverage this vulnerability to execute any arbitrary commands on the affected devices. This could lead to complete system compromise, exfiltration of data, or network intrusion.”