Description
The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.
Problem types
CWE-288: Authentication Bypass Using an Alternate Path or Channel
Product status
Firmware version 5.5.27_20190111
Firmware version 5.5.13_20180720
Firmware version 5.5.36_20190709
Credits
HD Moore of runZero discovered this vulnerability and Tod Beardsley of runZero reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-294-06
www.runzero.com/...ories/raisecom-ssh-bypass-cve-2025-11534/