---
id: CVE-2021-25680
title: >-
  The AdTran Personal Phone Manager software is vulnerable to multiple reflected
  cross-site scripting (XSS) issues
summary: >-
  The AdTran Personal Phone Manager software is vulnerable to multiple reflected
  cross-site scripting (XSS) issues. These issues impact at minimum versions
  10.8.1 and below but potentially impact later versions as well since they have
  not …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: adtran
product: personal_phone_manager
affected:
  - personal_phone_manager <= 10.8.1
published: '2021-04-20'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-25680'
references:
  - url: >-
      http://packetstormsecurity.com/files/162269/Adtran-Personal-Phone-Manager-10.8.1-Cross-Site-Scripting.html
    label: cve@mitre.org
  - url: >-
      https://github.com/3ndG4me/AdTran-Personal-Phone-Manager-Vulns/blob/main/CVE-2021-25680.md
    label: cve@mitre.org
  - url: 'http://adtran.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/162269/Adtran-Personal-Phone-Manager-10.8.1-Cross-Site-Scripting.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/3ndG4me/AdTran-Personal-Phone-Manager-Vulns/blob/main/CVE-2021-25680.md
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02465
epssPercentile: 0.83782
exploitAvailable: true
ingestedAt: '2026-07-05T02:00:01.585Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-25T08:20:38.341Z'
---

## Overview

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

## Affected

- `personal_phone_manager <= 10.8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
