CVE-2025-7635 Details
Description
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
A vulnerability allowing unauthenticated Telnet access has been identified in the Calix GigaCenter ONT models 844E, 844G, 844GE, and 854GE. This vulnerability arises from the Telnet service being exposed via the Quantenna interface IP, after the Broadcom System-on-Chip completes its initialization. The exposed Telnet service allows unauthorized users to gain root access to the device.
The vulnerability has been patched in the R12.2.13.4 update, available to authorized users. Users should contact their Broadband Service Provider to request the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fluidattacks.com/advisories/sal | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://fluidattacks.com/advisories/sal | [email protected] | ExploitMitigationThird Party Advisory |
| https://revers3everything.com/calix-case-five-0-days-five-cves/ | [email protected] | Third Party Advisory |
| https://www.calix.com | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| calix calix gigacenter ont | 844e 844g 844ge 854ge |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | Initial Analysis | [email protected] |
| Sep 12, 2025 | CVE Modified | [email protected] |
| Sep 10, 2025 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | New CVE Received | [email protected] |