CVE-2025-0890

CRITICAL EXPLOITED

Zyxel Vmg4325-b10a Firmware - Authentication Bypass

Title source: rule

Description

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

Scores

CVSS v3 9.8
EPSS 0.0123
EPSS Percentile 79.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2026-01-20

Classification

CWE
CWE-522 CWE-287
Status published

Affected Products (14)

zyxel/vmg4325-b10a_firmware
zyxel/sbg3500-n000_firmware
zyxel/vmg1312-b10a_firmware
zyxel/vmg1312-b10b_firmware
zyxel/vmg1312-b10e_firmware
zyxel/vmg3312-b10a_firmware
zyxel/vmg3313-b10a_firmware
zyxel/vmg3926-b10b_firmware
zyxel/vmg4380-b10a_firmware
zyxel/vmg8324-b10a_firmware
zyxel/vmg8924-b10a_firmware
zyxel/sbg3300-n000_firmware
zyxel/sbg3300-nb00_firmware
zyxel/sbg3500-nb00_firmware

Timeline

Published Feb 04, 2025
Tracked Since Feb 18, 2026