Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
The vulnerability lies in improper access control (CWE-284) in the Adtran 411 ONT device firmware. The mechanism responsible for changing the administrator password does not verify the identity or permissions of the requester, allowing any attacker with network access to the device to trigger this operation. An attacker can remotely, without authentication and without user interaction, overwrite the administrator password with their own value.
Attacker gains full administrative control over the Adtran 411 ONT device, leading to loss of confidentiality and integrity of configuration and data. Legitimate administrators may be permanently locked out from managing the device.
Apply patches available from the manufacturer according to references. Until the fix is implemented, it is recommended to restrict network access to the device management interface exclusively to trusted IP addresses using firewall or ACL rules.
Adtran 411 ONT with firmware version L80.00.0011.M2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NAdtran 411
HWAdtranall versionsAdtran 411 Firmware
OSAdtranl80.00.0011.m2
Related vulnerabilities
Privilege escalation w Adtran 411 ONT — krytyczna podatność LPE
Słabe domyślne hasła w urządzeniu Adtran 411 ONT
Command injection w usłudze telnet urządzeń Adtran 411 ONT — eskalacja do root
Command injection w interfejsie webowym Adtran 411 ONT — eskalacja do root
RCE w routerach SmartRG SR506n i SR510n via funkcja ping host