Zyxel DSL CPE Insecure Default Credentials Vulnerability in Telnet Function

Vulnerability

A vulnerability exists in certain legacy Zyxel DSL CPE models, including the VMG4325-B10A, due to insecure default credentials for the Telnet function. This vulnerability allows an attacker to access the management interface if administrators do not change the default credentials. The issue is present in the VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the device's management interface via Telnet, allowing for potential command execution on the device.

Remediation

Users are advised to change the default Telnet credentials. For ISPs, please contact your Zyxel sales or service representatives for further details.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.0
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.