Junglewise Threat Intelligence

CVE-2026-19745: Calix GigaSpire denial of service in Web Management Interface

CVE-2026-19745 · Severity: medium · CVSS 4.3 · Published 2026-08-13

Executive brief

Calix GigaSpire is a gateway device used to manage broadband connections and home network services. A flaw in its web-based management interface allows an attacker to remotely cause the service to become unavailable by manipulating session parameters, disrupting network operations for affected customers.

Technical details

A denial-of-service vulnerability exists in the utilities_configurationsave.cgi file within Calix GigaSpire's Web Management Interface. The flaw arises from insufficient validation of the sessionKey parameter, which can be manipulated to crash or disable the management service. The attack is network-accessible and requires no authentication or user interaction. An attacker can exploit this to temporarily render the device's management interface unavailable, though the core gateway functionality may persist. A patch is not yet available; the vendor was notified early but has not responded.

Affected products

  • Calix GigaSpire 26.1.0

Timeline

  • 2026-08-13: disclosed
  • other: Exploit published; vendor notified but did not respond

References