CISA's list that day

11 February 2025

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Zyxel DSL CPE Devices and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-40890DSL CPE OS Command InjectionZyxel DSL CPE DevicesPatch soon0.21
CVE-2024-40891DSL CPE OS Command InjectionZyxel DSL CPE DevicesPatch soon0.22
CVE-2025-21391Storage Link FollowingMicrosoft WindowsPatch soon0.02
CVE-2025-21418Ancillary Function Driver for WinSock Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.02

Other changes that day

  1. CVE-2024-40890 Zyxel DSL CPE DevicesEdited: notes.
  2. CVE-2024-40891 Zyxel DSL CPE DevicesEdited: notes.