CVE-2025-35021: Antek Abilis Cpx Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.

Affected products

  • Antek Abilis Cpx Firmware: before 9.0.7 (fixed in 9.0.7)

Published 2025-11-04. Last modified 2026-06-17.