Vulnerability record · CVE-2021-40859 · published 7 December 2021
CVE-2021-40859: Auerswald COMpact 5500R backdoors grant full admin access
Auerswald · Compact 5500r Firmware
Auerswald COMpact 5500R firmware versions 7.8A and 8.0B contain backdoors reachable through the web-based management application. An attacker who can reach that interface obtains full administrative control of the device, which is a critical exposure for a telephony system. The record does not describe the backdoor mechanism itself, only its effect.
Description
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable backdoor yielding full administrative control, with a 9.8 CVSS score and very high EPSS, makes this an urgent exposure despite the absence of KEV listing.
What it is
Auerswald COMpact 5500R firmware versions 7.8A and 8.0B contain backdoors reachable through the web-based management application. An attacker who can reach that interface obtains full administrative control of the device, which is a critical exposure for a telephony system. The record does not describe the backdoor mechanism itself, only its effect.
Impact
An attacker gains full administrative access to the device, allowing configuration changes, credential or data access, and potential interception or disruption of telephony services. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The flaw is reached over the network through the web-based management application, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description says access to the web management application is the precondition, so the interface must be reachable by the attacker.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.71979 (99.4th percentile), and the vendor advisory references are tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.
What to do
- Apply the vendor fix for COMpact 5500R 7.8A and 8.0B; check Auerswald advisories for the corrected firmware and upgrade immediately.
- If no fix is available, isolate the web management interface from untrusted networks and restrict it to a dedicated management VLAN or VPN.
- Block internet exposure of the device management port and audit any existing port-forwarding or firewall rules that publish it.
- Rotate administrative credentials and review device configuration for unauthorized accounts or changes.
- Monitor vendor channels for further guidance, since the record does not name a specific patched version.
Detection
- Review web management access logs for logins or requests from unexpected source IPs, especially without prior authentication.
- Compare device configuration against a known-good baseline to spot unauthorized admin accounts, routes or forwarding rules.
- Alert on management interface traffic originating outside the approved management network.
- Hunt for anomalous outbound connections from the device that could indicate abuse of administrative access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses | Third Party Advisory |
| https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-007/-auerswald-compact-multiple-backdoors | ExploitThird Party Advisory |
| https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses | Third Party Advisory |
| https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-007/-auerswald-compact-multiple-backdoors | ExploitThird Party Advisory |
Track CVE-2021-40859 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2021-40859), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.