Executive brief
A vulnerability in the GCOM EPON 1GE fiber optic networking device allows unauthorized individuals to take over administrative sessions. The device, which provides high-speed internet and video services to homes and businesses, fails to use secure tokens to identify users, relying instead only on their IP address. This means an attacker sharing or spoofing a legitimate user's IP address can gain full control over the device's settings without needing a password, potentially leading to service disruption or unauthorized network monitoring.
Technical details
The web management interface of the GCOM EPON 1GE ONU (firmware C00R371V00B01) suffers from an authentication bypass (CWE-290) due to improper session management. The device identifies authenticated sessions solely by the client's source IP address and does not implement session cookies, tokens, or unique identifiers. An attacker on the network can gain full administrative access by spoofing the IP address of a currently or recently authenticated user. This allows for arbitrary administrative actions without knowledge of valid credentials. No patch has been explicitly confirmed in the provided advisory text.
Affected products
- GCOM Technologies EPON 1GE ONU C00R371V00B01
Timeline
- 2026-02-23: disclosed
- 2026-02-23: advisory