CVE-2025-2171: Aviatrix Controller

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

Affected products

Published 2025-06-23. Last modified 2026-06-17.