CVE-2025-67015: Comtech Cdm-625 Firmware

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

Affected products

  • Comtech Cdm-625 Firmware: version 2.5.1 only
  • Comtech Cdm-625a Firmware: version 2.5.1 only

Published 2025-12-26. Last modified 2026-06-17.