PT-2026-46230 · Unknown · Gx Earth 2022 Ont
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GX Earth 2022 ONT models
Description
An issue exists due to a hardcoded RSA private key within the device firmware. A remote attacker could extract this cryptographic private key to decrypt HTTPS traffic and perform Man-in-the-Middle (MITM) attacks, which involve an attacker secretly relaying and possibly altering the communications between two parties who believe they are directly communicating with each other.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gx Earth 2022 Ont