Here is a follow-on rundown of CVE-2024-40890, affecting the HTTP interface of EOL Zyxel CPE routers. Don't forget to filter user input for `\n` 😉 Pairs quite nicely with the supervisor (backdoor) / zyuser user accounts.
vulncheck.com/blog/zyxel-h...