Adtran 411 ONT Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Adtran 411 ONT, specifically in firmware version L80.00.0011.M2. This vulnerability allows attackers to gain elevated privileges through unspecified vectors. The issue was discovered during a security audit, which noted several vulnerabilities, including weak user passwords, command injection opportunities via Telnet and the web interface, and the ability for unprivileged users to access configuration files containing admin passwords.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain elevated rights and access sensitive functions or data.

Reproduction

The vulnerability can be reproduced by accessing the device's serial console through a 4-port header on the mainboard. This header can be accessed from outside the unit by connecting to the internal pins through the device's casing. Once connected, the console outputs boot logs and presents a login prompt, where a root shell can be obtained.

Remediation

Users are advised to update to version 24.3, where this vulnerability has been addressed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.