**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
Firmware in Zyxel VMG4325-B10A devices (version 1.00(AAFR.4)C0_20170615) and related models contains factory-set credentials for the Telnet service. Administrators have the technical capability to change these credentials, however, if they do not, an attacker can log into the management interface using publicly known default authentication credentials. The vulnerability is classified as CWE-287 (improper authentication) and CWE-522 (insufficiently protected credentials).
An attacker gains full access to the device's management interface via Telnet, which may lead to device takeover, modification of its configuration, breach of confidentiality and integrity of transmitted data, and potential use of the device as an entry point to the internal network.
The manufacturer has designated these devices as independently supported (UNSUPPORTED WHEN ASSIGNED) — official patches may not be available. Default authentication credentials for Telnet functionality must be changed immediately, and ideally the Telnet service should be completely disabled and replaced with a more secure protocol (e.g., SSH). It is recommended to consider replacing devices with supported models. Detailed recommendations from the manufacturer are available in the official Zyxel security advisory from 2025-02-04.
Zyxel VMG4325-B10A firmware 1.00(AAFR.4)C0_20170615, Zyxel SBG3500-N000, and Zyxel VMG1312-B10A — devices designated as legacy (independently supported at the time of CVE assignment), specific firmware versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZyxel Sbg3300 N000
HWZyxelall versionsZyxel Sbg3300 N000 Firmware
OSZyxelall versionsZyxel Sbg3300 Nb00
HWZyxelall versionsZyxel Sbg3300 Nb00 Firmware
OSZyxelall versionsZyxel Sbg3500 N000
HWZyxelall versionsZyxel Sbg3500 N000 Firmware
OSZyxelall versionsZyxel Sbg3500 Nb00
HWZyxelall versionsZyxel Sbg3500 Nb00 Firmware
OSZyxelall versionsZyxel Vmg1312 B10a
HWZyxelall versionsZyxel Vmg1312 B10a Firmware
OSZyxelall versionsZyxel Vmg1312 B10b
HWZyxelall versionsZyxel Vmg1312 B10b Firmware
OSZyxelall versionsZyxel Vmg1312 B10e
HWZyxelall versionsZyxel Vmg1312 B10e Firmware
OSZyxelall versionsZyxel Vmg3312 B10a
HWZyxelall versionsZyxel Vmg3312 B10a Firmware
OSZyxelall versionsZyxel Vmg3313 B10a
HWZyxelall versionsZyxel Vmg3313 B10a Firmware
OSZyxelall versionsZyxel Vmg3926 B10b
HWZyxelall versionsZyxel Vmg3926 B10b Firmware
OSZyxelall versionsZyxel Vmg4325 B10a
HWZyxelall versionsZyxel Vmg4325 B10a Firmware
OSZyxelall versionsZyxel Vmg4380 B10a
HWZyxelall versionsZyxel Vmg4380 B10a Firmware
OSZyxelall versionsZyxel Vmg8324 B10a
HWZyxelall versionsZyxel Vmg8324 B10a Firmware
OSZyxelall versionsZyxel Vmg8924 B10a
HWZyxelall versionsZyxel Vmg8924 B10a Firmware
OSZyxelall versions
Related vulnerabilities
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the ...
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands...
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG...
Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia