Abilis CPX Fallback Shell Connection Relay
Vulnerability Description
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35021
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- HD Moore
- Tod Beardsley
- AHA!
References
- https://www.runzero.com/advisories/abilis-cpx-authentication-bypass-cve-2025-35021/
- https://takeonme.org/gcves/GCVE-1337-2025-00000000000000000000000000000000000000000000000001011111111111011111111110000000000000000000000000000000000000000000000000000000100
- https://support.abilis.net/relnotes/cpx2k/R9.0.html#R9.0.7
Affected Vendor
Abilis
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.