CVE-2025-0890

CRITICALCVSS 9.8/10EPSS 12.83%

Last modified

CVE-2025-0890 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.. EPSS estimates a 12.83% chance of exploitation in the next 30 days.

Description

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
12.83%

95.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelVmg4325-B10a FirmwareAll versions
ZyxelSbg3500-N000 FirmwareAll versions
ZyxelVmg1312-B10a FirmwareAll versions
ZyxelVmg1312-B10b FirmwareAll versions
ZyxelVmg1312-B10e FirmwareAll versions
ZyxelVmg3312-B10a FirmwareAll versions
ZyxelVmg3313-B10a FirmwareAll versions
ZyxelVmg3926-B10b FirmwareAll versions
ZyxelVmg4380-B10a FirmwareAll versions
ZyxelVmg8324-B10a FirmwareAll versions
ZyxelVmg8924-B10a FirmwareAll versions
ZyxelSbg3300-N000 FirmwareAll versions
ZyxelSbg3300-Nb00 FirmwareAll versions
ZyxelSbg3500-Nb00 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-0890?
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
How severe is CVE-2025-0890?
CVE-2025-0890 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 12.83% probability of exploitation in the next 30 days.
How do I fix CVE-2025-0890?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-0890?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST