CVE-2025-28229

CRITICAL

Orban Optimod 5950 Firmware - Improper Access Control

Title source: rule
STIX 2.1

Description

Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

Scores

CVSS v3 9.8
EPSS 0.0028
EPSS Percentile 51.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
orban/optimod_5950_firmware 1.0.0.2
Published Apr 18, 2025
Tracked Since Feb 18, 2026