SSH Server Weak Password Vulnerability in Thermo Fisher Ion Torrent OneTouch 2
CVE-2025-53963

9.8CRITICAL

Key Information:

Vendor
CVE Published:
4 December 2025

What is CVE-2025-53963?

A significant security issue affects the Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices, where an SSH server exposed on the default port 22 can be exploited. The root account has a weak default password (ionadmin), combined with a lack of enforced password change policies, allowing an attacker with network access to gain root code execution. It is important to note that this vulnerability pertains only to products no longer supported by the vendor.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.