CISA's list that day
11 February 2025
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Zyxel DSL CPE Devices and Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-40890DSL CPE OS Command Injection | Zyxel DSL CPE Devices | Patch soon | 0.21 | ||
| CVE-2024-40891DSL CPE OS Command Injection | Zyxel DSL CPE Devices | Patch soon | 0.22 | ||
| CVE-2025-21391Storage Link Following | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-21418Ancillary Function Driver for WinSock Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 |