Junglewise Threat Intelligence

CVE-2026-45433: GX Group GX Earth 2022 hardcoded RSA private key

CVE-2026-45433 · Severity: info · CVSS 8.7 · Published 2026-06-04

Executive brief

GX Earth 2022 devices are fiber-optic modems used to provide high-speed internet to homes and businesses. A security flaw exists where these devices use a fixed, secret digital key that is identical across all units and can be discovered by outsiders. An attacker who obtains this key can intercept and read supposedly secure web traffic (HTTPS) passing through the device, potentially exposing sensitive user data or login credentials.

Technical details

A hardcoded cryptographic key vulnerability (CWE-321) exists in GX Earth 2022 ONT firmware. The device utilizes a static RSA private key for its cryptographic operations, which is embedded directly within the firmware image. A remote attacker can extract this key from the firmware and use it to decrypt intercepted HTTPS traffic or facilitate Man-in-the-Middle (MITM) attacks against the device's web management interface. This bypasses the confidentiality protections typically afforded by TLS. The vendor has released firmware updates (E2022-3.1.5A, E2022-3.1.8AV, or E2022-1.2ASL) to address this issue.

Affected products

  • GX Group (GX India) Earth 2022 ONT E2022 - 3.1.2A, 3.1.5AV, E2022 1.1ASL

Timeline

  • 2026-06-04: disclosed: Initial disclosure by CERT-In
  • 2026-06-04: advisory: NVD record published

References

Related threats