PT-2025-4087 · Zyxel · Zyxel Vmg4325-B10A
Published
2025-02-04
·
Updated
2025-12-15
·
CVE-2025-0890
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615
Description
The issue concerns insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A, which could allow an attacker to log in to the management interface if administrators fail to change the default credentials. This includes improper authentication via Telnet and OS Command Injections.
Recommendations
For Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615, consider changing the default Telnet credentials to prevent unauthorized access. As a temporary workaround, restrict access to the Telnet function until the issue is resolved.
Fix
Using Hardcoded Credentials
Insufficiently Protected Credentials
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zyxel Vmg4325-B10A