Junglewise Threat Intelligence

CVE-2026-45431: GX Group GX Earth ONT OS command injection in diagnostic functions

CVE-2026-45431 · Severity: info · CVSS 8.7 · Published 2026-06-04

Executive brief

GX Earth optical network terminals (ONTs), which provide fiber-optic internet connectivity to homes and businesses, contain a security flaw in their web management interface. An attacker with basic login credentials can exploit diagnostic tools to take full control of the device. This could allow an unauthorized user to disrupt internet service, monitor network traffic, or use the device as a foothold for further attacks on the internal network.

Technical details

An OS command injection vulnerability (CWE-78) exists in GX Earth 2022 and 1010 ONT models due to improper neutralization of user-supplied input within multiple diagnostic functions of the web-based management interface. An authenticated remote attacker can exploit this by submitting specially crafted input to these diagnostic fields, leading to the execution of arbitrary system commands. Successful exploitation grants the attacker root-level access to the underlying operating system. The vulnerability is addressed in firmware versions E2022-3.1.5A, E2022-3.1.8AV, E2022-1.2ASL, and E1010-1.2ASL.

Affected products

  • GX Group Earth 2022 E2022-3.1.2A, 3.1.5AV, E2022 1.1ASL
  • GX Group Earth 1010 E1010-1.1ASL

Timeline

  • 2026-06-04: advisory: Advisory published by CERT-In (CIVN-2026-0288)
  • 2026-06-04: disclosed: CVE-2026-45431 published to NVD

References