PT-2025-4087 · Zyxel · Zyxel Vmg4325-B10A

Published

2025-02-04

·

Updated

2025-12-15

·

CVE-2025-0890

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615
Description The issue concerns insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A, which could allow an attacker to log in to the management interface if administrators fail to change the default credentials. This includes improper authentication via Telnet and OS Command Injections.
Recommendations For Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0 20170615, consider changing the default Telnet credentials to prevent unauthorized access. As a temporary workaround, restrict access to the Telnet function until the issue is resolved.

Fix

Using Hardcoded Credentials

Insufficiently Protected Credentials

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01344
CVE-2025-0890

Affected Products

Zyxel Vmg4325-B10A