CVE-2025-0890
published 2025-02-04CVE-2025-0890: **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version…
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
13.54%
96.1th percentile
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | vmg4325-b10a_firmware | <= 1.00(AAFR.4)C0_20170615 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)"; flow:established,to_server; content:"admin|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060090; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)"; flow:established,to_server; content:"zyuser|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060091; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)"; flow:established,to_server; content:"supervisor|0d 00|zyad1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060089; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
bytes↗
admin|0d 00|1234
bytes↗
zyuser|0d 00|1234
bytes↗
supervisor|0d 00|zyad1234
- →Monitor Telnet (TCP/23) sessions to network devices for login attempts using the default credential pairs: admin:1234, zyuser:1234, and supervisor:zyad1234. The supervisor account is a hidden privileged account granting full system access. ↗
- →CVE-2025-0890 is actively chained with CVE-2024-40891 (Telnet command injection via libcms_cli.so): initial access via default credentials is followed by shell metacharacter injection through commands such as ifconfig, ping, or tftp to achieve RCE. ↗
- →Affected devices include VMG1312-B10A/B/E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300, and SBG3500. Prioritize detection on perimeter and internal segments where these EoL devices may still be present. ↗
- ·No patch will be issued. Zyxel has confirmed all affected devices are EoL and recommends replacement. Detection/blocking controls are the only available mitigation. ↗
- ·The vulnerability was confirmed against firmware version 1.00(AAFR.4)C0_20170615 on VMG4325-B10A; other listed models are also affected but specific firmware versions are not enumerated in the sources. ↗
- ·The supervisor account is a hidden/undocumented account; administrators may be unaware of its existence and therefore unable to change its default credentials even if they intend to harden the device. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q2vf-jq2x-689c: **UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1
ghsa_unreviewed·2025-02-04
CVE-2025-0890 [CRITICAL] CWE-287 GHSA-q2vf-jq2x-689c: **UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
VulnCheck
Zyxel vmg4325-b10a_firmware Improper Authentication
vulncheck·2025·CVSS 9.8
CVE-2025-0890 [CRITICAL] Zyxel vmg4325-b10a_firmware Improper Authentication
Zyxel vmg4325-b10a_firmware Improper Authentication
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Affected: Zyxel vmg4325-b10a_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Suricata
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)
suricata·2025-02-14·CVSS 9.8
CVE-2025-0890 [CRITICAL] ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)"; flow:established,to_server; content:"admin|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060090; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
Suricata
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)
suricata·2025-02-14·CVSS 9.8
CVE-2025-0890 [CRITICAL] ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)"; flow:established,to_server; content:"zyuser|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060091; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
Suricata
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)
suricata·2025-02-14·CVSS 9.8
CVE-2025-0890 [CRITICAL] ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)
ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)"; flow:established,to_server; content:"supervisor|0d 00|zyad1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060089; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
No public exploits indexed.
2025-02-04
Published
Exploited in the wild