CVE-2025-0890 describes a critical vulnerability in the legacy Zyxel VMG4325-B10A DSL CPE, specifically in firmware version 1.00(AAFR.4)C0_20170615, due to insecure default Telnet credentials. This allows unauthenticated attackers to gain full control of the device's management interface if the default credentials are not changed. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, there is significant community discussion and media coverage indicating active exploitation and Zyxel's decision not to patch these end-of-life devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg4325-b10a_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:sbg3500-n000_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10a_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10b_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:vmg1312-b10e_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE
Feb 4, 2025Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE
Feb 4, 2025