← Vulnerability feed

Vulnerability record · CVE-2021-40859 · published 7 December 2021

CVE-2021-40859: Auerswald COMpact 5500R backdoors grant full admin access

Auerswald · Compact 5500r Firmware

Auerswald COMpact 5500R firmware versions 7.8A and 8.0B contain backdoors reachable through the web-based management application. An attacker who can reach that interface obtains full administrative control of the device, which is a critical exposure for a telephony system. The record does not describe the backdoor mechanism itself, only its effect.

9.8 CVSS 3.1 Critical EPSS 72% · top 0.6%
9.8CVSS 3.1 base score, v2 10.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable backdoor yielding full administrative control, with a 9.8 CVSS score and very high EPSS, makes this an urgent exposure despite the absence of KEV listing.

What it is

Auerswald COMpact 5500R firmware versions 7.8A and 8.0B contain backdoors reachable through the web-based management application. An attacker who can reach that interface obtains full administrative control of the device, which is a critical exposure for a telephony system. The record does not describe the backdoor mechanism itself, only its effect.

Impact

An attacker gains full administrative access to the device, allowing configuration changes, credential or data access, and potential interception or disruption of telephony services. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reached over the network through the web-based management application, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description says access to the web management application is the precondition, so the interface must be reachable by the attacker.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.71979 (99.4th percentile), and the vendor advisory references are tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.

What to do

  • Apply the vendor fix for COMpact 5500R 7.8A and 8.0B; check Auerswald advisories for the corrected firmware and upgrade immediately.
  • If no fix is available, isolate the web management interface from untrusted networks and restrict it to a dedicated management VLAN or VPN.
  • Block internet exposure of the device management port and audit any existing port-forwarding or firewall rules that publish it.
  • Rotate administrative credentials and review device configuration for unauthorized accounts or changes.
  • Monitor vendor channels for further guidance, since the record does not name a specific patched version.

Detection

  • Review web management access logs for logins or requests from unexpected source IPs, especially without prior authentication.
  • Compare device configuration against a known-good baseline to spot unauthorized admin accounts, routes or forwarding rules.
  • Alert on management interface traffic originating outside the approved management network.
  • Hunt for anomalous outbound connections from the device that could indicate abuse of administrative access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40859 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2021-40859), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.