A recent Mandiant Red Team engagement revealed two critical vulnerabilities in Aviatrix Controller, which could lead to full system compromise. These flaws include an authentication bypass (CVE-2025-2171) and a command injection vulnerability (CVE-2025-2172). #Aviatrix #CVE20252171 #CVE20252172
Keypoints
- The vulnerabilities allow attackers to gain administrative control over Aviatrix cloud management systems.
- The authentication bypass exploits a weak password reset mechanism with a 6-digit token that remains valid for 15 minutes.
- Successful exploitation was demonstrated after 16 hours of brute-force attempts on the default βadminβ account.
- Post-authentication, the command injection flaw enables remote code execution with root privileges.
- Aviatrix has issued patches and advises immediate updates and restricts public controller access to mitigate risks.
Read More: https://gbhackers.com/aviatrix-cloud-controller-flaw/