PT-2025-4087 · Zyxel · Zyxel Vmg4325-B10A

Publicado

2025-02-04

·

Atualizado

2025-12-15

·

CVE-2025-0890

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615
Description The issue concerns insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A, which could allow an attacker to log in to the management interface if administrators fail to change the default credentials. This includes improper authentication via Telnet and OS Command Injections.
Recommendations For Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615, consider changing the default Telnet credentials to prevent unauthorized access. As a temporary workaround, restrict access to the Telnet function until the issue is resolved.

Correção

Using Hardcoded Credentials

Insufficiently Protected Credentials

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-01344
CVE-2025-0890

Produtos afetados

Zyxel Vmg4325-B10A