← Back

Vmg4325 B10a Firmware

vmg4325-b10a_firmware

Vendor: Zyxel • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zyxel
14Sbg3300 N000 Firmware
Sbg3300 Nb00 FirmwareSbg3500 N000 Firmware+11 more
Dec 15, 2025
Feb 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management int...Show more
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.Show less
1Zyxel
14Sbg3300 N000 Firmware
Sbg3300 Nb00 FirmwareSbg3500 N000 Firmware+11 more
Oct 27, 2025
Feb 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticate...Show more
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.Show less
1Zyxel
14Sbg3300 N000 Firmware
Sbg3300 Nb00 FirmwareSbg3500 N000 Firmware+11 more
Oct 27, 2025
Feb 4, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attack...Show more
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.Show less