CVE-2025-22940 Details
Description
Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
A vulnerability in the Adtran 411 ONT, specifically in firmware version L80.00.0011.M2, has been identified that allows unauthorized attackers to arbitrarily change the admin password. This issue arises from incorrect access control, enabling unprivileged users to modify admin account credentials. Additionally, the vulnerability allows any user account to access and dump a configuration file containing the admin password.
Users are advised to update to version 24.3, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view | CISA-ADP | ExploitThird Party Advisory |
| https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view | [email protected] | ExploitThird Party Advisory |
| https://lanrat.com/posts/adtran-isp-hacking/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| adtran 411 firmware | l80.00.0011.m2 |
CPE
Remediation
| |
| adtran 411 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | CVE Modified | [email protected] |
| Jun 20, 2025 | Initial Analysis | [email protected] |
| Apr 1, 2025 | CVE Modified | CISA-ADP |
| Mar 31, 2025 | New CVE Received | [email protected] |