First published: Tue Feb 04 2025(Updated: )
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel VMG4325-B10A firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0890 has a high severity rating due to the use of insecure default credentials.
To fix CVE-2025-0890, change the default Telnet credentials immediately after setup.
CVE-2025-0890 specifically affects the Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615.
CVE-2025-0890 can allow unauthorized remote access to the router's management interface, potentially compromising the device.
CVE-2025-0890 is considered a known vulnerability and not a zero-day, as it has been assigned and reported.