CVE Feed

    Dashboard / CVE / CVE-2025-0890

    CVE-2025-0890

    **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

    Published:Feb 4, 2025
    Last Modified:Dec 15, 2025
    EPS:Feb 4, 2025
    EPSS Score:0.01045
    CVSS Score:9.8

    Affected Products

    Vendor
    Zyxel
    Product
    Sbg3300-n000
    Vendor
    Zyxel
    Product
    Sbg3300-n000 Firmware
    Vendor
    Zyxel
    Product
    Sbg3300-nb00
    Vendor
    Zyxel
    Product
    Sbg3300-nb00 Firmware
    Vendor
    Zyxel
    Product
    Sbg3500-n000
    Vendor
    Zyxel
    Product
    Sbg3500-n000 Firmware
    Vendor
    Zyxel
    Product
    Sbg3500-nb00
    Vendor
    Zyxel
    Product
    Sbg3500-nb00 Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10a
    Vendor
    Zyxel
    Product
    Vmg1312-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10b
    Vendor
    Zyxel
    Product
    Vmg1312-b10b Firmware
    Vendor
    Zyxel
    Product
    Vmg1312-b10e
    Vendor
    Zyxel
    Product
    Vmg1312-b10e Firmware
    Vendor
    Zyxel
    Product
    Vmg3312-b10a
    Vendor
    Zyxel
    Product
    Vmg3312-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg3313-b10a
    Vendor
    Zyxel
    Product
    Vmg3313-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg3926-b10b
    Vendor
    Zyxel
    Product
    Vmg3926-b10b Firmware
    Vendor
    Zyxel
    Product
    Vmg4325-b10a
    Vendor
    Zyxel
    Product
    Vmg4325-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg4380-b10a
    Vendor
    Zyxel
    Product
    Vmg4380-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg8324-b10a
    Vendor
    Zyxel
    Product
    Vmg8324-b10a Firmware
    Vendor
    Zyxel
    Product
    Vmg8924-b10a
    Vendor
    Zyxel
    Product
    Vmg8924-b10a Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High