PT-2021-16750 · Adtran · Netvanta 7060+2

·

CVE-2021-25680

·

Published

2021-04-20

·

Updated

2024-08-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AdTran Personal Phone Manager versions 10.8.1 and earlier
Description The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact versions 10.8.1 and below, and potentially later versions as well, since they have not previously been disclosed. The affected appliances, NetVanta 7060 and NetVanta 7100, are considered End of Life and will not be patched.
Recommendations For versions 10.8.1 and earlier, consider disabling any features that may be susceptible to cross-site scripting attacks until a patch is available, however, since the affected appliances are End of Life, a patch will not be provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25680

Affected Products

Adtran Personal Phone Manager
Netvanta 7060
Netvanta 7100