CRITICAL🇵🇱 Wersja polska

CVE-2025-22940

CVSS 9.1v3.1pub. 2025-03-31upd. 2025-08-18

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

🤖 AI Analysis
How it works

The vulnerability lies in improper access control (CWE-284) in the Adtran 411 ONT device firmware. The mechanism responsible for changing the administrator password does not verify the identity or permissions of the requester, allowing any attacker with network access to the device to trigger this operation. An attacker can remotely, without authentication and without user interaction, overwrite the administrator password with their own value.

Impact

Attacker gains full administrative control over the Adtran 411 ONT device, leading to loss of confidentiality and integrity of configuration and data. Legitimate administrators may be permanently locked out from managing the device.

Mitigation & patch

Apply patches available from the manufacturer according to references. Until the fix is implemented, it is recommended to restrict network access to the device management interface exclusively to trusted IP addresses using firewall or ACL rules.

Who is affected

Adtran 411 ONT with firmware version L80.00.0011.M2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Adtran 411

    HW
    Adtran
    all versions
  • Adtran 411 Firmware

    OS
    Adtran
    l80.00.0011.m2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-22937CRITICAL9.8PL ✓same product

Privilege escalation w Adtran 411 ONT — krytyczna podatność LPE

CVE-2025-22938CRITICAL9.8PL ✓same product

Słabe domyślne hasła w urządzeniu Adtran 411 ONT

CVE-2025-22939CRITICAL9.8PL ✓same product

Command injection w usłudze telnet urządzeń Adtran 411 ONT — eskalacja do root

CVE-2025-22941CRITICAL9.8PL ✓same product

Command injection w interfejsie webowym Adtran 411 ONT — eskalacja do root

CVE-2022-37661CRITICAL9.8PL ✓same vendor

RCE w routerach SmartRG SR506n i SR510n via funkcja ping host