AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-0890

CRITICAL · CVSS 9.8 EPSS 13.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-04 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 13.5% probability of exploitation in the next 30 days.

CVE
CVE-2025-0890
Severity
CRITICAL
CVSS
9.8
EPSS
13.54%

Original NVD Description

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.

Related CVEs

Other vulnerabilities affecting the same vendor(s)