CVE-2021-25309 describes a critical vulnerability in the Gigaset DX600A v41.00-175 device, where the telnet administrator service on port 650 lacks lockout or throttling mechanisms. This, combined with a weak 4-digit password policy, allows unauthenticated remote attackers to easily brute-force credentials and gain full administrative access. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a high risk of complete compromise (confidentiality, integrity, and availability). While there is no evidence of active exploitation, exploit code, or significant community discussion, the ease of exploitation makes it a serious concern for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v41.00-175CPE matchmatch criteria | cpe:2.3:o:gigaset:dx600a_firmware:v41.00-175:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.