Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-56241. PoCs published by Amir Hossein Jamshidi.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated password change vulnerability in the Aztech DSL5005EN router by sending a crafted POST request to the 'sysAccess.asp' endpoint. It allows an attacker to change the admin password without prior authentication.
Description
Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.
Exploits (1)
This exploit demonstrates an unauthenticated password change vulnerability in the Aztech DSL5005EN router by sending a crafted POST request to the 'sysAccess.asp' endpoint. It allows an attacker to change the admin password without prior authentication.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H