CVE-2021-25681 describes a data exfiltration vulnerability in AdTran Personal Phone Manager 10.8.1, affecting NetVanta 7060 and 7100 appliances. This allows attackers to use exposed web servers as DNS redirectors to tunnel arbitrary data over DNS. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to significant data confidentiality impact. While not actively exploited in the wild, a public exploit (EDB-49787) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.8.1CPE matchmatch criteria | cpe:2.3:a:adtran:personal_phone_manager:10.8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.