Infinera MTC-9 Remote Shell Access Vulnerability via Password-less Accounts

Vulnerability

A vulnerability in the remote shell service (RSH) of Infinera MTC-9, specifically in version R22.1.1.0275 prior to R23.0, allows attackers to gain system access by exploiting password-less user accounts. This access is achieved by initiating a reverse shell, which can be used to execute commands on the affected device.

Impact

Exploitation of this vulnerability allows for unauthorized system access via a reverse shell, enabling the execution of commands on the affected device.

Added: Dec 8, 2025, 10:18 AM
Updated: Dec 8, 2025, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.