CVE-2025-28229 Details
Description
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.
A broken access control vulnerability has been identified in the Orban OPTIMOD 5950, specifically in Firmware Version 1.0.0.2 and System Version 2.2.15. This vulnerability allows attackers to bypass authentication and gain administrative privileges through improper access control in the web interface login page. By executing specific JavaScript commands in the browser's developer console, an unauthenticated attacker can manipulate client-side authentication checks, effectively gaining full control over the device.
Administrators are advised to move authentication checks to the server side, remove exposed JavaScript functions from the client-side console, and implement secure authentication mechanisms. Until a patch is available, it is recommended to disable external access to the web interface, monitor logs for unauthorized activities, and use Web Application Firewall rules to block unauthorized requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28229 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28229 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| orban optimod 5950 firmware | 1.0.0.2 |
CPE
Remediation
| |
| orban optimod 5950 | 2.2.15 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2025 | Initial Analysis | [email protected] |
| Apr 22, 2025 | CVE Modified | CISA-ADP |
| Apr 18, 2025 | New CVE Received | [email protected] |