Executive brief
A security flaw in GCOM EPON 1GE fiber optic network terminals allows users with low-level access to take over the entire device. By exploiting weak access controls, an attacker can modify restricted settings and download unencrypted backup files containing the administrator's password. This could lead to a complete loss of control over the network hardware, allowing an attacker to intercept traffic or disrupt internet services.
Technical details
A privilege escalation vulnerability exists in GCOM EPON 1GE firmware version C00R371V00B01 due to improper access control (CWE-284). The web management interface and configuration API fail to properly restrict administrative functions, allowing a user with 'User' level privileges to modify settings intended only for the 'Administrator' role. Furthermore, the device's backup feature generates unencrypted configuration files that contain sensitive credentials, including the administrator password in plaintext. A remote authenticated attacker with low privileges can exploit these flaws to extract the admin password and gain full administrative control over the device.
Affected products
- GCOM EPON 1GE C00R371V00B01
Timeline
- 2025-11-10: disclosed: Initial disclosure date reported by researcher
- 2026-02-24: advisory: CVE published to NVD