PT-2025-39314 · Aztech · Dsl5005En

Published

2025-09-24

·

Updated

2025-09-24

·

CVE-2025-56241

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Aztech DSL5005EN firmware version 1.00.AZ 2013-05-10 and other versions (affected versions not specified)
Description An unauthenticated attacker can modify the administrator password by sending a specially crafted POST request to the sysAccess.asp endpoint. Successful exploitation grants full administrative control of the router without requiring authentication.
Recommendations Apply a firmware update if available. As a temporary workaround, restrict access to the sysAccess.asp endpoint.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-56241

Affected Products

Dsl5005En