Record summary

CVE-2025-56241 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 17, 2025 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBAztech DSL5005EN Router - 'sysAccess.asp' Admin Password Change (Unauthenticated)ExploitDB exploitby Amir Hossein JamshidiNot analyzed1 file
ExploitDB

PoC details

References

4