CVE-2025-53963 Details
Description
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can achieve root code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
A vulnerability exists in the Thermo Fisher Ion Torrent OneTouch 2 system, specifically in devices with the catalog number INS1005527. These devices run an SSH server on the default port 22. The root account is protected by a weak default password, 'ionadmin', and there is no enforced password change policy for the root account. As a result, an attacker with network access can gain root privileges and execute code. This vulnerability affects only unsupported products.
Users are advised to change the default root password and review their network configuration to minimize exposure to this vulnerability. Additionally, ensure that the device is not connected to the public Internet without proper security measures, such as a firewall.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-521 | Weak Password Requirements | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| thermofisher ion torrent onetouch 2 firmware | All versions |
CPE
Remediation
| |
| thermofisher ion torrent onetouch 2 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 16, 2025 | Initial Analysis | [email protected] |
| Dec 5, 2025 | CVE Modified | CISA-ADP |
| Dec 4, 2025 | New CVE Received | [email protected] |