Loading
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Use CWE-78, Zyxel vendor hub and Emg6726-B10a Firmware product page to widen CVE-2024-9200 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-13942, CVE-2025-7673 and CVE-2025-13943 for nearby disclosures in the same product family.