Description
The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.
Scores
CVSS v4
9.3
EPSS
0.0012
EPSS Percentile
30.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-288
Status
published
Products (3)
Raisecomm/RAX701-GC-WP-01 P200R002C52
Firmware version 5.5.27_20190111
Raisecomm/RAX701-GC-WP-01 P200R002C53
Firmware version 5.5.13_20180720
Raisecomm/RAX701-GC-WP-01 P200R002C53
Firmware version 5.5.36_20190709
Published
Oct 21, 2025
Tracked Since
Feb 18, 2026