60
CVE-2025-0890
—CVSS 3.1
9.8 critical
EPSS
14%p96
Published
()
Modified
Description
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
- Vendors
- zyxel
- Products
- vmg4325-b10a firmware, sbg3500-n000 firmware, vmg1312-b10a firmware, vmg1312-b10b firmware, vmg1312-b10e firmware, vmg3312-b10a firmware, vmg3313-b10a firmware, vmg3926-b10b firmware, vmg4380-b10a firmware, vmg8324-b10a firmware, vmg8924-b10a firmware, sbg3300-n000 firmware
- Weakness
- CWE-287, CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H