6.5 CVE-2025-35021
Enriched by CISA Exploit
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.
https://nvd.nist.gov/vuln/detail/CVE-2025-35021
Categories
CWE-1188 : Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) insecure default variable initialization in BIOS firmware for a hardware board allows DoS A generic database browser interface has a default mode that exposes a web server to the network, allowing queries to the database.
References
cve@takeonme.org Exploit
| https://support.abilis.net/relnotes/cpx2k/R9.0.html#R9.0.7 Release Notes |
| https://takeonme.org/gcves/GCVE-1337-2025-00000000000000000000000000000000000... Exploit Mitigation Third Party Advisory |
| https://www.runzero.com/advisories/abilis-cpx-authentication-bypass-cve-2025-... Exploit Mitigation Third Party Advisory |
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| Abilis | CPX |
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|---|---|
| Configuration 1 | ||
| AND | ||
| cpe:2.3:o:antek:abilis_cpx_firmware:*:*:*:*:*:*:*:* | < 9.0.7 | |
| Running on/with | ||
| cpe:2.3:h:antek:abilis_cpx_2000:-:*:*:*:*:*:*:* | ||
REMEDIATION
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| https://takeonme.org/gcves/GCVE-1337-2025-00000000000000000000000000000000000... |
| https://www.runzero.com/advisories/abilis-cpx-authentication-bypass-cve-2025-... |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| 665 | Exploitation of Thunderbolt Protection Flaws |
Very High |
MITRE
Techniques
| id | description |
|---|---|
| T1211 | Exploitation for Defensive Evasion |
| T1542.002 | Pre-OS Boot:Component Firmware |
| T1556 | Modify Authentication Process |
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | |
Mitigations
| id | description |
|---|---|
| M1051 | Update software regularly by employing patch management for internal enterprise endpoints and servers. |
| M1051 | Perform regular firmware updates to mitigate risks of exploitation and/or abuse. |
| M1018 | Ensure that proper policies are implemented to dictate the the secure enrollment and deactivation of authentication mechanisms, such as MFA, for user accounts. |
| © 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation. | |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
