*UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
Configuration 15 (hide)
| AND |
|
15 Dec 2025, 21:02
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3500-n000:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:* |
|
| First Time |
Zyxel vmg1312-b10e
Zyxel vmg4380-b10a Firmware Zyxel sbg3500-nb00 Zyxel vmg4325-b10a Firmware Zyxel sbg3500-n000 Firmware Zyxel vmg1312-b10a Zyxel vmg1312-b10e Firmware Zyxel vmg3312-b10a Firmware Zyxel vmg8324-b10a Firmware Zyxel sbg3300-n000 Firmware Zyxel vmg1312-b10b Zyxel Zyxel sbg3500-nb00 Firmware Zyxel sbg3300-nb00 Zyxel sbg3300-nb00 Firmware Zyxel vmg3312-b10a Zyxel vmg8924-b10a Firmware Zyxel vmg3926-b10b Firmware Zyxel vmg8924-b10a Zyxel sbg3300-n000 Zyxel vmg4325-b10a Zyxel vmg1312-b10b Firmware Zyxel vmg3313-b10a Firmware Zyxel vmg3926-b10b Zyxel vmg4380-b10a Zyxel vmg1312-b10a Firmware Zyxel vmg3313-b10a Zyxel vmg8324-b10a Zyxel sbg3500-n000 |
|
| References | () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 - Vendor Advisory | |
| CWE | CWE-522 |
04 Feb 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-02-04 11:15
Updated : 2025-12-15 21:02
NVD link : CVE-2025-0890
Mitre link : CVE-2025-0890
CVE.ORG link : CVE-2025-0890
JSON object : View
- vmg1312-b10e_firmware
- vmg4325-b10a
- sbg3500-nb00_firmware
- vmg8924-b10a_firmware
- sbg3300-n000_firmware
- vmg3926-b10b_firmware
- vmg3312-b10a
- vmg3313-b10a_firmware
- vmg8924-b10a
- vmg3926-b10b
- vmg4325-b10a_firmware
- vmg1312-b10a_firmware
- sbg3300-n000
- vmg1312-b10b_firmware
- sbg3500-n000
- vmg1312-b10e
- sbg3500-n000_firmware
- vmg1312-b10a
- sbg3500-nb00
- vmg1312-b10b
- vmg8324-b10a
- vmg4380-b10a
- vmg4380-b10a_firmware
- vmg3312-b10a_firmware
- sbg3300-nb00_firmware
- vmg3313-b10a
- sbg3300-nb00
- vmg8324-b10a_firmware