CVE-2021-25679

MEDIUM

AdTran Personal Phone Manager <= 10.8.1 - Authenticated Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-25679. PoCs published by 3ndG4me.

AI-analyzed exploit summary This is a detailed writeup describing an authenticated stored XSS vulnerability in Adtran Personal Phone Manager 10.8.1. The vulnerability allows malicious JavaScript execution via the 'emailAddress' and 'emailAddress2' parameters in the change email address form.

Description

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched

Exploits (2)

exploitdb WRITEUP
by 3ndG4me · textwebappshardware
https://www.exploit-db.com/exploits/49785

This is a detailed writeup describing an authenticated stored XSS vulnerability in Adtran Personal Phone Manager 10.8.1. The vulnerability allows malicious JavaScript execution via the 'emailAddress' and 'emailAddress2' parameters in the change email address form.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Adtran Personal Phone Manager v10.8.1
Auth required
Prerequisites: Authenticated access to the Adtran Personal Phone Manager interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 3 stars
by 3ndG4me · poc
https://github.com/3ndG4me/AdTran-Personal-Phone-Manager-Vulns

This repository contains a detailed technical writeup for CVE-2021-25679, an authenticated stored XSS vulnerability in AdTran Personal Phone Manager. It includes proof-of-concept payloads, affected parameters, and a timeline of disclosure.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: AdTran Personal Phone Manager v10.8.1
Auth required
Prerequisites: Authenticated access to the AdTran Personal Phone Manager
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 5.4
EPSS 0.0286
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
adtran/personal_phone_manager < 10.8.1
Published Apr 20, 2021
Tracked Since Feb 18, 2026