CVE-2025-0890: Critical severity Zyxel VMG4325-B10A vulnerability
UNSUPPORTED WHEN ASSIGNED Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C020170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0890?
CVE-2025-0890 has a high severity rating due to the use of insecure default credentials.
How do I fix CVE-2025-0890?
To fix CVE-2025-0890, change the default Telnet credentials immediately after setup.
Which devices are affected by CVE-2025-0890?
CVE-2025-0890 specifically affects the Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615.
What risks are associated with CVE-2025-0890?
CVE-2025-0890 can allow unauthorized remote access to the router's management interface, potentially compromising the device.
Is CVE-2025-0890 a zero-day vulnerability?
CVE-2025-0890 is considered a known vulnerability and not a zero-day, as it has been assigned and reported.