CVE-2025-0890

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3500-n000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*

History

15 Dec 2025, 21:02

Type Values Removed Values Added
CPE cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3500-n000:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:*
CWE CWE-522
First Time Zyxel vmg3312-b10a
Zyxel sbg3500-n000
Zyxel vmg8924-b10a
Zyxel vmg3312-b10a Firmware
Zyxel vmg4380-b10a
Zyxel vmg8324-b10a Firmware
Zyxel sbg3300-n000 Firmware
Zyxel vmg1312-b10e
Zyxel
Zyxel vmg1312-b10a Firmware
Zyxel sbg3500-nb00 Firmware
Zyxel vmg4325-b10a Firmware
Zyxel sbg3300-nb00 Firmware
Zyxel vmg1312-b10e Firmware
Zyxel vmg4380-b10a Firmware
Zyxel sbg3300-nb00
Zyxel vmg1312-b10b Firmware
Zyxel vmg3926-b10b
Zyxel sbg3300-n000
Zyxel vmg8324-b10a
Zyxel vmg3313-b10a
Zyxel vmg4325-b10a
Zyxel vmg3926-b10b Firmware
Zyxel sbg3500-nb00
Zyxel vmg1312-b10a
Zyxel sbg3500-n000 Firmware
Zyxel vmg8924-b10a Firmware
Zyxel vmg1312-b10b
Zyxel vmg3313-b10a Firmware
Summary
  • (es) **NO SOPORTADO CUANDO SE ASIGNÓ** Las credenciales predeterminadas inseguras para la función Telnet en el firmware 1.00(AAFR.4)C0_20170615 del CPE DSL heredado Zyxel VMG4325-B10A podrían permitir que un atacante inicie sesión en la interfaz de administración si los administradores tienen la opción de cambiar las credenciales predeterminadas pero no lo hacen.
References () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 - () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-insecure-default-credentials-vulnerabilities-in-certain-legacy-dsl-cpe-02-04-2025 - Vendor Advisory

04 Feb 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 11:15

Updated : 2025-12-15 21:02


NVD link : CVE-2025-0890

Mitre link : CVE-2025-0890

CVE.ORG link : CVE-2025-0890


JSON object : View

Products Affected

zyxel

  • vmg3313-b10a_firmware
  • vmg3313-b10a
  • sbg3500-n000
  • sbg3300-n000_firmware
  • sbg3500-nb00_firmware
  • vmg4325-b10a_firmware
  • vmg1312-b10e
  • sbg3300-nb00
  • vmg1312-b10b
  • vmg4380-b10a
  • vmg8324-b10a
  • vmg8324-b10a_firmware
  • vmg8924-b10a
  • vmg3312-b10a
  • sbg3500-nb00
  • vmg1312-b10a
  • vmg3926-b10b_firmware
  • vmg1312-b10b_firmware
  • vmg3926-b10b
  • sbg3300-nb00_firmware
  • vmg1312-b10a_firmware
  • vmg1312-b10e_firmware
  • vmg8924-b10a_firmware
  • vmg3312-b10a_firmware
  • vmg4380-b10a_firmware
  • vmg4325-b10a
  • sbg3300-n000
  • sbg3500-n000_firmware
CWE
CWE-287

Improper Authentication

CWE-522

Insufficiently Protected Credentials