CVE-2026-45431 Details
Description
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device. Successful exploitation of this vulnerability could allow the attacker to perform remote code execution with root privileges on the targeted device.
A command injection vulnerability has been identified in GX Earth ONT models, specifically in the web management interface of GX Earth 2022 versions E2022-3.1.2A, 3.1.5AV, and E2022-1.1ASL, as well as GX Earth 1010 version E1010-1.1ASL. This vulnerability arises from improper handling of user-supplied input in multiple diagnostic functions, enabling authenticated remote attackers to inject and execute arbitrary operating system commands on the affected devices. Successful exploitation grants root privileges, allowing for remote code execution.
Users are advised to upgrade GX Earth 2022 to the latest firmware versions E2022-3.1.5A, E2022-3.1.8AV, or E2022-1.2ASL. For GX Earth 1010, upgrade to the latest firmware version E1010-1.2ASL.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0288 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GX INDIA GX Earth 2022 | E2022-3.1.2A E2022-3.1.5AV E2022-1.1ASL |
CPE
Remediation
| |
| GX INDIA GX Earth 1010 | E1010-1.1ASL |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion