CVE-2025-56241

High severity, CVSS 7.5. EPSS: 6.7% chance of exploitation in the next 30 days.

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.

Published 2025-09-24. Last modified 2026-06-17.