Description

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

INFO

Published Date :

2025-12-26T00:00:00.000Z

Last Modified :

2025-12-26T16:28:22.470Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-67015 vulnerability.

Vendors Products
Comtech
  • Cdm-625
  • Cdm-625 Firmware
  • Cdm-625a
  • Cdm-625a Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact