CVE-2025-53963CRITICAL 9.8EPSS p30.5%

CVE-2025-53963CVE-2025-53963

Description

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can achieve root code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.39% probability of exploitation · percentile 30.5% · 2026-06-18T12:00:27Z
Published2025-12-04
Last modified2025-12-16

Underlying weaknesses· 1

CWE-521

References

  1. https://assets.thermofisher.com/TFS-Assets/LSG/manuals/MAN0014388_IonOneTouch2Sys_UG.pdf
  2. https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/Ion_OneTouch_2_and_Torrent_Suite_Software.pdf
  3. https://tools.thermofisher.cn/content/sfs/brochures/One_Touch_2_Spec_Sheet.pdf

1

TypeTargetConfidenceTier
WeaknessWeak Password Requirementscwe-5210%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-54304
CVE
CVE-2025-54303
CVE
CVE-2025-8731
CVE
CVE-2026-41085
CVE
CVE-2025-48416
CVE
CVE-2025-28202
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.