Junglewise Threat Intelligence

CVE-2026-45432: GX Group GX Earth ONT cleartext credential transmission in web interface

CVE-2026-45432 · Severity: info · CVSS 8.7 · Published 2026-06-04

Executive brief

GX Earth optical network terminals (ONTs), which provide fiber broadband connectivity to homes and businesses, are vulnerable to credential theft. The device's management interface sends usernames and passwords in unencrypted plaintext over the network. An attacker who can monitor network traffic could steal these credentials to gain full unauthorized access to the device and its settings.

Technical details

A cleartext transmission of sensitive information vulnerability (CWE-319) exists in the web management interface of GX Earth 2022 and 1010 ONT models. The root cause is the use of unencrypted HTTP for transmitting user credentials during authentication. A remote attacker positioned on the network path can intercept this traffic to obtain administrative credentials. This unauthorized access can lead to full device compromise. Users are advised to upgrade to firmware versions E2022-3.1.5A, E2022-3.1.8AV, E2022-1.2ASL, or E1010-1.2ASL as appropriate.

Affected products

  • GX Group Earth 2022 ONT E2022 - 3.1.2A, 3.1.5AV, E2022 1.1ASL
  • GX Group Earth 1010 ONT E1010-1.1ASL

Timeline

  • 2026-06-04: disclosed: Vulnerability reported by Anmol Bakshi via CERT-In
  • 2026-06-04: advisory
  • 2026-06-04: patched

References

Related threats