cbcvebase.
CVE-2025-0890
published 2025-02-04

CVE-2025-0890: **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version…

PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
13.54%
96.1th percentile
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

Affected

1 ranges
VendorProductVersion rangeFixed in
zyxelvmg4325-b10a_firmware<= 1.00(AAFR.4)C0_20170615

Detection & IOCsextracted from sources · hover to see the quote

snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (admin) (CVE-2025-0890)"; flow:established,to_server; content:"admin|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060090; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (zyuser) (CVE-2025-0890)"; flow:established,to_server; content:"zyuser|0d 00|1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060091; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
snort
alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Zyxel DSL CPE Management Interface Default Credentials (supervisor) (CVE-2025-0890)"; flow:established,to_server; content:"supervisor|0d 00|zyad1234"; reference:url,vulncheck.com/blog/zyxel-telnet-vulns#cve-2025-0890-default-credentials; reference:cve,2025-0890; classtype:attempted-admin; sid:2060089; rev:1; metadata:affected_product Zyxel, attack_target Networking_Equipment, created_at 2025_02_14, cve CVE_2025_0890, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_02_14; target:dest_ip;)
bytes
admin|0d 00|1234
bytes
zyuser|0d 00|1234
bytes
supervisor|0d 00|zyad1234
  • Monitor Telnet (TCP/23) sessions to network devices for login attempts using the default credential pairs: admin:1234, zyuser:1234, and supervisor:zyad1234. The supervisor account is a hidden privileged account granting full system access.
  • CVE-2025-0890 is actively chained with CVE-2024-40891 (Telnet command injection via libcms_cli.so): initial access via default credentials is followed by shell metacharacter injection through commands such as ifconfig, ping, or tftp to achieve RCE.
  • Affected devices include VMG1312-B10A/B/E, VMG3312-B10A, VMG3313-B10A, VMG3926-B10B, VMG4325-B10A, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, SBG3300, and SBG3500. Prioritize detection on perimeter and internal segments where these EoL devices may still be present.
  • ·No patch will be issued. Zyxel has confirmed all affected devices are EoL and recommends replacement. Detection/blocking controls are the only available mitigation.
  • ·The vulnerability was confirmed against firmware version 1.00(AAFR.4)C0_20170615 on VMG4325-B10A; other listed models are also affected but specific firmware versions are not enumerated in the sources.
  • ·The supervisor account is a hidden/undocumented account; administrators may be unaware of its existence and therefore unable to change its default credentials even if they intend to harden the device.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.