**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel sbg3300-n000
Zyxel sbg3300-n000 Firmware Zyxel sbg3300-nb00 Zyxel sbg3300-nb00 Firmware Zyxel sbg3500-n000 Zyxel sbg3500-n000 Firmware Zyxel sbg3500-nb00 Zyxel sbg3500-nb00 Firmware Zyxel vmg1312-b10a Zyxel vmg1312-b10a Firmware Zyxel vmg1312-b10b Zyxel vmg1312-b10b Firmware Zyxel vmg1312-b10e Zyxel vmg1312-b10e Firmware Zyxel vmg3312-b10a Zyxel vmg3312-b10a Firmware Zyxel vmg3313-b10a Zyxel vmg3313-b10a Firmware Zyxel vmg3926-b10b Zyxel vmg3926-b10b Firmware Zyxel vmg4325-b10a Zyxel vmg4380-b10a Zyxel vmg4380-b10a Firmware Zyxel vmg8324-b10a Zyxel vmg8324-b10a Firmware Zyxel vmg8924-b10a Zyxel vmg8924-b10a Firmware |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:h:zyxel:sbg3300-n000:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3300-nb00:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3500-n000:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:sbg3500-nb00:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg1312-b10e:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3312-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3313-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg3926-b10b:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4325-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg4380-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8324-b10a:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:vmg8924-b10a:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3300-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:sbg3500-nb00_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3312-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3313-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3926-b10b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4380-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8324-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg8924-b10a_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel sbg3300-n000
Zyxel sbg3300-n000 Firmware Zyxel sbg3300-nb00 Zyxel sbg3300-nb00 Firmware Zyxel sbg3500-n000 Zyxel sbg3500-n000 Firmware Zyxel sbg3500-nb00 Zyxel sbg3500-nb00 Firmware Zyxel vmg1312-b10a Zyxel vmg1312-b10a Firmware Zyxel vmg1312-b10b Zyxel vmg1312-b10b Firmware Zyxel vmg1312-b10e Zyxel vmg1312-b10e Firmware Zyxel vmg3312-b10a Zyxel vmg3312-b10a Firmware Zyxel vmg3313-b10a Zyxel vmg3313-b10a Firmware Zyxel vmg3926-b10b Zyxel vmg3926-b10b Firmware Zyxel vmg4325-b10a Zyxel vmg4380-b10a Zyxel vmg4380-b10a Firmware Zyxel vmg8324-b10a Zyxel vmg8324-b10a Firmware Zyxel vmg8924-b10a Zyxel vmg8924-b10a Firmware |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2025-02-12T20:51:26.709Z
Reserved: 2025-01-30T18:17:03.472Z
Link: CVE-2025-0890
Updated: 2025-02-12T20:42:13.868Z
Status : Analyzed
Published: 2025-02-04T11:15:08.880
Modified: 2025-12-15T21:02:44.180
Link: CVE-2025-0890
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:27Z