Skip to main content

Vendor archive

adtran CVEs

Beta · best-effort

20 CVEs tagged to vendor adtran8 Critical, 6 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-22941

Published Mar 31, 2025

A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-22940

Published Mar 31, 2025

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-22939

Published Mar 31, 2025

A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-22937

Published Mar 31, 2025

An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-31970

Published Jul 24, 2024

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39345

Published Jul 24, 2024

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19648

Published Mar 27, 2019

An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary comma…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4564

Published Dec 29, 2005

The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4565

Published Dec 29, 2005

Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-4566

Published Dec 29, 2005

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via craft…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0292

Published Apr 19, 2000

The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1