Cyber Posture

CVE-2025-22940

CriticalPublic PoC

Published: 31 March 2025

Published
31 March 2025
Modified
18 August 2025
KEV Added
Patch
CVSS Score 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0029 52.3th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems.

Security Summary

CVE-2025-22940 is an incorrect access control vulnerability affecting the Adtran 411 ONT running firmware version L80.00.0011.M2. It enables unauthorized attackers to arbitrarily set the admin password, as documented under CWE-284. The vulnerability has a CVSS v3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating critical severity due to its network accessibility, low attack complexity, and lack of prerequisites.

Remote attackers require no privileges or user interaction to exploit this flaw over the network. Successful exploitation allows them to set the admin password, granting high-level confidentiality and integrity impacts, such as full administrative control over the device without affecting availability.

Mitigation details and advisories are referenced in the following sources: https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view, https://lanrat.com/posts/adtran-isp-hacking/, and https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view.

Details

CWE(s)
CWE-284

Affected Products

adtran
411 firmware
l80.00.0011.m2

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1098 Account Manipulation Persistence
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems.
Why these techniques?

The CVE describes an unauthenticated remote vulnerability allowing arbitrary admin password setting on a public-facing ONT device, enabling exploitation via T1190 for initial access and facilitating T1098 by permitting unauthorized account password changes.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References