CVE-2025-22939

CRITICAL

Adtran 411 Firmware L80.00.0011.M2 - Command Injection via Telnet Service

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.

Scores

CVSS v3 9.8
EPSS 0.0244
EPSS Percentile 82.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
adtran/411_firmware l80.00.0011.m2
Published Mar 31, 2025
Tracked Since Feb 18, 2026