CVE-2025-22941
Published: 31 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-22941 is a command injection vulnerability (CWE-77) present in the web interface of the Adtran 411 ONT running firmware version L80.00.0011.M2. Published on 2025-03-31T15:15:43.873, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical due to its high impact on confidentiality, integrity, and availability.
Remote attackers with network access to the affected device can exploit this vulnerability without authentication privileges or user interaction. Successful exploitation enables privilege escalation to root and execution of arbitrary commands on the device.
Advisories and further details are available in the provided references, including https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view and https://lanrat.com/posts/adtran-isp-hacking/.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Command injection in unauthenticated public web interface enables remote exploitation (T1190), arbitrary Unix shell command execution (T1059.004), and privilege escalation to root (T1068).