CVE-2025-71056 Details
Description
Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
A session hijacking vulnerability has been identified in the GCOM EPON 1GE ONU model, specifically in the C00R371V00B01 firmware version. The issue arises from improper session management in the web management interface, where the application relies solely on the client's IP address for session identification. This lack of secure session cookies or tokens allows an attacker on the local network to spoof the IP address of an authenticated user, gaining unauthorized access to the administrative interface and the ability to perform arbitrary actions without valid credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 23, 2026CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| GCOM EPON 1GE ONU | C00R371V00B01 |
CPE
Remediation
| |
| H18GN-100-1 | All versions |
CPE
Remediation
| |
| H18GN-421-1 | All versions |
CPE
Remediation
| |
| H18GN-421-3 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | New CVE Received | [email protected] |
Volerion