Zyxel VMG4005-B50A/VMG4005-B60A Firmware Release Note
Version: V5.17(ABQA.3)C0
Date: June 6, 2025
Author: CHI-HAO, LO
Supported Platforms
Zyxel VMG4005-B50A / Zyxel VMG4005-B60A
Versions
- Bootbase Version: V1.59 | 03/21/2024 19:41:20
- Firmware version: V5.17(ABQA.3)C0
- Kernel version: 4.1.52
- VMG4005-B50A Annex A DSL modem code version: A2pvfbH046y4
- VMG4005-B60A Annex B DSL modem code version: B2pvfbH046w
- DSL driver version: d27n
Default Settings in Firmware
Refer to the *.rom in the fw release package.
Please use the website http://jsoneditoronline.org/ to open the *.rom.
Public Domain Software Announcements
External Information: Known Issues
Modules | Issue | Risk Impact Information |
---|---|---|
Modifications in 5.17(ABQA.3)C0 | ||
FCS based on 5.17(ABQA.3)b13 |
|
|
|
|
|
Modifications in 5.17(ABQA.3)b13 | ||
5.17(ABQA.3)b13 based on 5.17(ABQA.3)b12 |
|
|
|
|
|
Security | [CVE-2024-8176] Zyxel-SI-1605 [Vulnerability] The libexpat open source library is vulnerable to DoS attacks through stack overflow | |
Modifications in 5.17(ABQA.3)b12 | ||
5.17(ABQA.3)b12 based on 5.17(ABQA.3)b11 |
|
|
EAA | WEB GUI meets the request of Europe EAA (European Accessibility Act) | |
|
|
|
Modifications in 5.17(ABQA.3)b11 | ||
5.17(ABQA.3)b11 based on 5.17(ABQA.3)b10 |
|
|
Webgui | [eITS#240701511][Studerus] Quick Start Wizard works not correct VMG4005-series/DM4200-B0/GM4100-BO Generic | |
|
|
|
Security | Zyxel-SI-1589 [Vulnerability] Post-authentication command injection vulnerability in the "DNSSever" parameter | |
Modifications in 5.17(ABQA.3)b10 | ||
5.17(ABQA.3)b10 based on 5.17(ABQA.3)b9 |
|
|
Webgui | [eITS#240701511][Studerus] Quick Start Wizard works not correct VMG4005-series/DM4200-B0/GM4100-BO Generic | |
|
|
|
Security | [CVE-2024-8748] [Zyxel-SI-1576] [Vulnerability] Unauthenticated buffer overflow in VMC8825-T50 | |
Modifications in 5.17(ABQA.3)b9 | ||
5.17(ABQA.3)b9 based on 5.17(ABQA.3)b8 |
|
|
|
|
|
Security | Zyxel-SI-1557 [Vulnerability] Unauthenticated heap buffer overflow in the libclinkc library [CVE-2024-38266,38267,38268,38269][Zyxel-SI-1559][Vulnerability] Multiple authenticated buffer overflow vulnerabilities in VMG8825-T50 |
|
Modifications in 5.17(ABQA.3)b8 | ||
5.17(ABQA.3)b8 based on 5.17(ABQA.3)b7 |
|
|
GUI | [eITS#231000299][mmc] missing feature "Additional Subnet" | |
|
|
|
Security | [Vulnerability] Zyxel-SI-1536 [Vulnerability] Buffer overflow vulnerability in the "traceroute" command of DX3300-T1 CPE | |
GUI | [eITS#240200870] [Kraftcom] Login Privilege can't be change | |
Modifications in 5.17(ABQA.3)b7 | ||
5.17(ABQA.3)b7 based on 5.17(ABQA.3)b6 |
|
|
|
|
|
Security | [eITS#230500907] [Vulnerability] Possible security flaw that allows to retrieve root password | |
Modifications in 5.17(ABQA.3)b6 | ||
5.17(ABQA.3)b6 based on 5.17(ABQA.3)b5 |
|
|
|
|
|
Security | [CVE-2022-4203,4304,4450][CVE-2023-0215~0217,0286,0401][ Zyxel-SI-1464] [Vulnerability] OpenSSL multiple vulnerabilities, for VMG4005-B50A/B60A Generic [CVE-2022-43389,43390,43391,43392][Zyxel-SI-1433] [Vulnerability] Buffer overflow vulnerabilities and command injection vulnerability |
|
Modifications in 5.17(ABQA.3)b5 | ||
5.17(ABQA.3)b5 based on 5.17(ABQA.3)b4 |
|
|
DSL | [eits # 220800988] [CETIN] VMG4005-B60A - VMG does not communicate on the WAN after reboot | |
Modifications in 5.17(ABQA.3)b4 | ||
5.17(ABQA.3)b4 based on 5.17(ABQA.3)b3 |
|
|
|
|
|
Modifications in 5.17(ABQA.3)b3 | ||
5.17(ABQA.3)b3 based on 5.17(ABQA.3)b2 |
|
|
|
|
|
Security | [Vulnerability] Infinite loop in BN_mod_sqrt() of OpenSSL when parsing certificates | |
Modifications in 5.17(ABQA.3)b2 | ||
5.17(ABQA.3)b2 based on 5.17(ABQA.3)b1 |
|
|
DSL | [eits # 211100588][A1] [Mantis-6494] New xDSL Phy version | |
|
|
|
Security | [VMG4005-B50A] [Zyxel-SI-1377] cleartext storage of sensitive information vulnerability | |
Modifications in 5.17(ABQA.3)b1 | ||
5.17(ABQA.3)b1 based on 5.15(ABQA.2)b5 |
|
|
WAN | [eits # 220101172] [Magenta] in combination as bridge forwarding the VLAN 33 tagged packets to LAN port to the CPE behind the Zyxel bridge | |
|
|
|
Modifications in 5.15(ABQA.2)b6 | ||
5.15(ABQA.2)b6 based on 5.15(ABQA.2)b5 |
|
|
Phy | [eits # 210700344] [A1] [Mantis-6341] New xDSL Phy | |
|
|
|
QOS | [eits # 200201321][A1] QOS is not working as expected | |
Modifications in 5.15(ABQA.2)b5 | ||
5.15(ABQA.2)b5 based on 5.15(ABQA.2)b4 |
|
|
certificate | [eits # 200900419] VMG4005-B60A - how to upload the certificate via TR069 [eits # 200100140] CETIN, VMG4005-B60A, FRQ - upload certificate via TR-069 |
|
Config | [eits #210601087] [Cetin] VMG4005-B60A default configuration change „Disable IPv4 Firewall, IPv6 Firewall and Dos Protection Blocking" | |
Bridge | [eits #200102989] CETIN, VMG4005-B60A - Bridge VlanCounter - counters (TRO69) | |
GUI | [eits #210301552] [A1] [Mantis-6172] Missing Portforwarding-Configuration (towards untagged NATed LAN-Clients) | |
EOC | [eits #210501155] [CETIN] VMG4005-B60A - new EOC registry format [eits #210501156] [CETIN] VMG4005-B60A - EOC registry values should take effect without RTFD |
|
|
|
|
Modifications in 5.15(ABQA.2)b4 | ||
TRO69 | [eits #200102982] CETIN, VMG4005-B60A - Bridge VlanCounter (TR069) [eits #200102937] CETIN, VMG4005-B60A - DSL Line parameters (TR069) [eits #200102938] CETIN, VMG4005-B60A - DSL Channel parameters (TRO69) [eits #200102951] CETIN, VMG4005-B60A - PTM Link parameters (TRO69) [eits #200102966] CETIN, VMG4005-B60A - Ethernet Link - NumberOfEntries (TR069) [eits #200102971] CETIN, VMG4005-B60A - Ethernet Link - LastChange (TR069) [eits #200102976] CETIN, VMG4005-B60A - Ethernet VLANTermination - NumberOfEntries (TR069) [eits #200102981] CETIN, VMG4005-B60A - Ethernet VLANTermination - LastChange (TR069) [eits #200102994] CETIN, VMG4005-B60A - PPP - InterfaceNumberOfEntries (TR069) [eits #200103028] CETIN, VMG4005-B60A - IP Interface - number of entries (TRO69) [eits #200103033] CETIN, VMG4005-B60A - IP interface - LAN - LastChange (TR069) [eits #200103040] CETIN, VMG4005-B60A - BondingGroup - BondedChannelNumber (TR069) [eits #210501559][CETIN] VMG4005-B60A - TRO69 - Parameter DefaultGatewaylface cannot be changed |
|
DSL | [eits #210501558][CETIN] VMG4005-B60A - both DSL lines are not synchronized at the same time | |
Time | [eits #210200498] [200814] VMG4005-B50B / NTP Sync issue in bridge mode | |
Modifications in 5.15(ABQA.2)b3 | ||
5.15(ABQA.2)b3 based on 5.15(ABQA.2)b2 |
|
|
FW | [eits #190800784] VMG4005-B60A - firmware banks management missing | |
certificate | [eits #190900339] VMG4005-B60A - local certificate used by TR-069 Client | |
GUI | [eits #190900329] VMG4005-B60A - DSL lines administrative status in WebGUI | |
Driver | [eits #210100660] New xDSL Phy [eits #210100664] New DSL Linedriver |
|
|
|
|
TR069 | [eits #190900225] VMG4005-B60A - bonding group statistics are not collected (TR069) [eits #190900220] VMG4005-B60A - DSL line and channel counters show wrong data in TR069 |
|
Security | [eits #190900228] VMG4005-B60A - VLAN termination [Vulnerability] Arbitrary remote code execution (RCE) on the device through an HTTP request [Vulnerability] Unauthenticated Denial-of-Service effectively disabling the device's web-interface [Common] [CVE-2020-1971][Openssl]Correctly compare EdiPartyName in GENERAL_NAME_cmp() Dnsmasq multiple vulnerabilities (DNSPooq) [Vulnerability] [EESBU] Vulnerabilities in Multiple Zyxel Equipment from Sec consult |
|
Modifications in 5.15(ABQA.2)b3 | ||
5.15(ABQA.2)b3 based on 5.15(ABQA.2)b2 |
|
|
kernel | [eits #200102928] CETIN, VMG4005-B60A - UNI Rx Errors | |
Modifications in 5.15(ABQA.2)b2 | ||
(TR069) | [eits #190900336] VMG4005-B60A - 64 bit counters (TR069) [eits #190900224] VMG4005-B60A - parameter counters of "TX and RX number of octets/bytes" are only 32 bit (TR069) [eits #191000361] WAN traffic status in WebGUI [eits #190900331] LAN traffic status in WebGUI |
|
certificate | [eits #190900363] VMG4005-B60A - certificate management in TR069 | |
ipv6 | [eits #200103023] CETIN, VMG4005-B60A - IPv6Capable (TR069) | |
GUI | [eits #190700654] VMG4005-B60A - Last status change of UNI | |
|
|
|
broadband | [eits #190900681] [Germany] Missing Annex J by VMG 4005-B60A | |
Modifications in 5.15(ABQA.2)b2 | ||
5.15(ABQA.2)b2 based on 5.15(ABQA.1)C0 |
|
|
modem | [eits #200400312] [A1] [Mantis-5607] New DSL Phy | |
dhcp | [eits #190801240] VMG4005-B60A - DHCP times in TR069 [eits #190800818] VMG4005-B60A - There is no info about configuration obtained via DHCP in WebGUI |
|
zhttpd | [eits #190900232] VMG4005-B60A - multipair DSL interface (bonding) statistics in WebGUI | |
Tr069 | [eits #200100140] CETIN, VMG4005-B60A, FRQ - upload certificate via TR-069 | |
webgui | [eits #190900327] VMG4005-B60A - Last status change of UNI (TR069) | |
webgui | [eits #190801236] VMG4005-B60A - provisioning code in WebGUI | |
|
|
|
log | certificates [eits #190900368] VMG4005-B60A - wrong number of certificates in TR069 | |
Modifications in 5.15(ABQA.1)C0 | ||
FCS based on 5.15(ABQA.1)b2 | ||
Modifications in 5.15(ABQA.1)b2 | ||
|
|
|
|
|
|
libzyutil | DUT reset configuration to default if ROMFILE block has an error bit | |
GUI_Vue | WAN mac address order should be changed for VMG4005 project | |
Modifications in 5.15(ABQA.1)b1 | ||
|
|
|
GUI | [eits #190900895] VMG4005-B60A - NTP servers obtained via DHCP are not written to configuration | |
|
|
|
GUI | [eits #191000604] VMG4005-B60A When accessing System Monitor > Traffic Status > WAN, system crashes | |
TR-069 | [eits #190900327] VMG4005-B60A - Last status change of UNI (TR069) [eits #190900227] VMG4005-B60A - Ethernet link statistics are not collected (TR069) |
|
Modifications in 5.15(ABQA.0)C0 | ||
|
|
|
RomFile | [eits #191000488] VMG4005-B50A The Parameter "Validate ACS certificate" must be activated by default | |
Modifications in 5.15(ABQA.0)b6 | ||
[FEATURE ENHACEMENT] | ||
1. | VMG4005-B60A - Counters of frames per VLAN | |
2. | VMG4005-B60A - QoS at Ethernet UNI | |
3. | VMG4005-B60A - management via IPv6 | |
4. | VMG4005-B60A - MAC address limiting | |
5. | New DSL physical modem code upgrade to A2pvfbH04501 for VMG4005-B50A | |
6. | New DSL physical driver to DSL-Phy 027h VMG 4005-B50A | |
[BUG FIX] | ||
1. | VMG4005-B60A - CPE does not send LPR (lost of power) | |
2. | Insufficient input validation for NTP server | |
3. | Port mirror can't be activate by the user "tccadmin" | |
Modifications in 5.15(ABQA.0)b5 | ||
[FEATURE ENHACEMENT] | ||
1. | VMG4005-B60A - Dropped frames counters at UNI | |
2. | VMG4005-B60A - Last status change of UNI | |
3. | VMG4005-B60A - DSCP of management traffic | |
4. | VMG4005-B60A - ATM PVC assignment according to VLAN | |
5. | VMG4005-B60A - MAC address learning | |
6. | VMG4005-B60A - MAC address table | |
7. | VMG4005-B60A - DHCP option 42 | |
8. | Feature request enhanced DSL Broadcom config VMG 4005-B50A | |
9. | DSL configuration MANTIS-5263 VMG 4005_B50A | |
10. | untypical STUN messages was send by the VMG4005 | |
11. | AW: Summary of the results ACS-Tests | |
12. | Inventory information not correct send to the DSLAM side VMG 4005-B50A | |
[BUG FIX] | ||
1. | DHCP Option(121) MANTIS-5265 works not correct VMG 4005-B50A | |
2. | Disable the IGMP proxy and the MLD Proxy by default | |
3. | VDSL2 SRA/G.inp Profile: Incorrect Att Bitrate on short distance loops VMG 4005-B50A | |
4. | VMG4005-B60A - Downloading of certificate | |
5. | VMG4005-B60A - vectoring issue | |
Modifications in 5.15(ABQA.0)b4 | ||
[FEATURE ENHACEMENT] | ||
1. | VMG4005-B60A - DNS server running | |
2. | VMG4005-B60A - not enough space to store 10 certificates | |
3. | New DSL physical driver VMG 4005-B50A | |
4. | Feature request support FDPS VMG 4005-B50A | |
5. | Disable the V43 G.hs toneset VMG 4005-B50A | |
6. | Feature request LongReach-VDSL2 mode VMG 4005-B50A | |
7. | VMG4005-B60A - Counters by different type of frame | |
8. | Inventory information not correct send to the DSLAM side VMG 4005-B50A | |
9. | Password Reset [MANTIS-5267] User Account 'tccadmin' VMG4005-B50A | |
10. | VMG4005-B60A - LAN interface shall be without IP address | |
11. | VMG4005-B60A - request to change default settings (the fixed password for the "root" user) | |
[BUG FIX] | ||
1. | VMG4005-B60A - Bridge interface is not fully transparent | |
2. | VMG4005-B60A - Even if ACS certificate validation is disabled device still performs certificate validation. | |
3. | Not possible to disable portmirror functuion VMG 4005-B50A | |
4. | VMG4005-B60A - Blocking of some L2CP messages | |
5. | L2CP transparent over the bridge VMG 4005-B50A | |
6. | VMG4005-B60A - Local management isolation | |
7. | VMG4005-B60A - RPC call | |
8. | VMG4005-B60A - RPC call (attributes) | |
9. | VMG4005-B60A - There are wrong values in some TR069 data model parameters | |
Modifications in 5.15(ABQA.0)b3 | ||
[FEATURE ENHACEMENT] | ||
1. | VMG4005-B60A - request to change default settings (disabling of "Validate ACS certificate") | |
[BUG FIX] | ||
1. | VMG4005-B60A - Bridge interface is not fully transparent | |
2. | VMG4005-B60A - insufficient physical layer performance | |
3. | GUI has no info show DSL bodning status | |
4. | 35b info does not display correctly in xDSL Statistics | |
5. | ACS service works not as expected VMG 4005-B50A | |
6. | NTP and DNS service works not via MGMT VLAN 4092 Prio 2 VMG 4005-B50A | |
7. | [kernel] Multiple TCP-based remote denial of service vulnerabilities (fixed about CVE-2019-11477, CVE-2019-11478, CVE-2019-11479) | |
Modifications in 5.15(ABQA.0)b2 | ||
[FEATURE ENHACEMENT] | ||
1. | VMG4005-B60A - WAN MAC address changing | |
2. | VMG4005-B60A - QoS, swapped CoS priorities | |
3. | There is DNS server running | |
4. | VMG4005-B60A - request to change default settings | |
5. | VMG4005-B60A - EOC register | |
6. | VMG4005-B60A - DNS server running | |
[BUG FIX] | ||
1. | VMG4005-B60A – WebGUI | |
2. | There are functionless leafs in TR069 data model (e.g. WiFi) | |
3. | There are wrong values in some TR069 data model parameters | |
4. | VMG4005-B60A - Device management becomes unusable after call TR069 RPC GetParameterAttributes | |
Modifications in 5.15(ABQA.0)b1 | ||
[FEATURE ENHACEMENT] | ||
1. | Disable both TCP port 161 and port 38400 (UPnP) | |
2. | Provide document of CLI commands | |
3. | [TR000185-4] [Req 2.1.5 2.1.8] Support Ethctl command and Ethernet UNI page | |
4. | [TR000185-4] [Req 2.1.7 4.1.2] Support JUMBO Frame | |
5. | [TR000185-4] [Req 4.1.1] Support transparent data transmission. | |
6. | [TR000185-4] [Req 4.3.2] CPE could be able to be set up not to learn any source MAC address of specific interfaces | |
7. | [TR000185-4] [Req 6.1.3.3] [GUI_vue] ADSL,VDSL--Dynamic IPv4 configuration | |
8. | [TR000185-4] [Req 6.2.1] Local management via Ethernet UNI | |
9. | [TR000185-4] [Req 6.3.4] CPE could reply LAN interface's content of 'Mac Address Table' including information of used vlan | |
10. | [TR000185-5] [Req 2.1.3] Additional device status information | |
11. | [TR000185-5] [Req 2.2.13.2] [User accounts] The Demarcation Device shall permit to define for each user account allowed management protocol(s) and input interface(s). | |
12. | [TR000185-5] [Req 3.2.1] HTTP/HTTPS remote access enable to the Demarcation Device | |
13. | [TR000185-5] [Req 3.2.2] HTTP/HTTPS local access disable to the Demarcation Device | |
[BUG FIX] | ||
1. | The System Info page does not show any values | |
2. | When internet connection is unavailable, it slows down the loading of the WebGUI. | |
3. | Insufficient physical layer performance | |
4. | Low throughput with bridge mode pure IPv4 traffic. | |
5. | VMG4005-B60A Port Mirror fail | |
6. | Bridge interface is not fully transparent | |
7. | Unstable remote access to Web GUI |