PT-2026-46194 · Gx India · Gx Earth 1010+1

·

CVE-2026-45431

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GX Earth ONT (affected versions not specified)
Description Improper handling of user-supplied input in multiple diagnostic functions within the web management interface allows an authenticated remote attacker to inject and execute arbitrary OS commands. Successful exploitation enables remote code execution with root privileges on the targeted device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45431

Affected Products

Gx Earth 1010
Gx Earth 2022