Description

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

INFO

Published Date :

2025-02-04T10:06:56.163Z

Last Modified :

2025-02-12T20:51:26.709Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2025-0890 vulnerability.

Vendors Products
Zyxel
  • Sbg3300-n000
  • Sbg3300-n000 Firmware
  • Sbg3300-nb00
  • Sbg3300-nb00 Firmware
  • Sbg3500-n000
  • Sbg3500-n000 Firmware
  • Sbg3500-nb00
  • Sbg3500-nb00 Firmware
  • Vmg1312-b10a
  • Vmg1312-b10a Firmware
  • Vmg1312-b10b
  • Vmg1312-b10b Firmware
  • Vmg1312-b10e
  • Vmg1312-b10e Firmware
  • Vmg3312-b10a
  • Vmg3312-b10a Firmware
  • Vmg3313-b10a
  • Vmg3313-b10a Firmware
  • Vmg3926-b10b
  • Vmg3926-b10b Firmware
  • Vmg4325-b10a
  • Vmg4325-b10a Firmware
  • Vmg4380-b10a
  • Vmg4380-b10a Firmware
  • Vmg8324-b10a
  • Vmg8324-b10a Firmware
  • Vmg8924-b10a
  • Vmg8924-b10a Firmware
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact