Adtran manufactures network access and edge-routing appliances such as the 411 and NetVanta series, which serve as critical connectivity points in carrier and enterprise deployments and present a substantial management and remote-access attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making timely patching essential for internet-facing or management-accessible instances. The exposure recurs across product lines through weakness classes including cross-site scripting, command injection, and OS command injection in web-management interfaces, reflecting the combination of embedded firmware, administrative UI complexity, and privileged command execution that characterizes edge networking devices. Defenders should prioritize inventory and access controls for these appliances and track firmware update cycles; live severity and exploitation data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adtran over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37661CRITICAL SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. | Sep 14, 2022 | 9.8 | 62 | NO | YES |
CVE-2021-25681HIGH AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager we | Apr 20, 2021 | 7.5 | 42 | NO | YES |
CVE-2021-25680MEDIUM The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but poten | Apr 20, 2021 | 6.1 | 34 | NO | YES |
CVE-2021-25679MEDIUM The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but | Apr 20, 2021 | 5.4 | 31 | NO | YES |
CVE-2025-22937CRITICAL An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors. | Mar 31, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-22940CRITICAL Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password. | Mar 31, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-22941CRITICAL A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands. | Mar 31, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-22939CRITICAL A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands. | Mar 31, 2025 | 9.8 | 26 | NO | NO |
CVE-2018-19648HIGH An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary comman | Mar 27, 2019 | 8.8 | 26 | NO | NO |
CVE-2025-22938CRITICAL Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords. | Mar 31, 2025 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adtran.
Media articles that mention a CVE ID that affects a product developed by Adtran — matched by CVE ID, not by vendor name.