CVE-2026-45432 Details
Description
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information, which could lead to unauthorized access to the targeted device.
A vulnerability exists in GX Earth ONT models due to user credentials being transmitted in plaintext over HTTP through the web management interface. This flaw allows remote attackers to intercept network traffic and capture sensitive authentication information, potentially leading to unauthorized access to the affected device. The vulnerability affects GX Earth 2022 models (versions E2022-3.1.2A, 3.1.5AV, and E2022-1.1ASL) and GX Earth 1010 models (version E1010-1.1ASL).
Users are advised to upgrade GX Earth 2022 to the latest firmware versions E2022-3.1.5A, E2022-3.1.8AV, or E2022-1.2ASL. GX Earth 1010 users should upgrade to the latest firmware version E1010-1.2ASL.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0288 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GX Earth 2022 | E2022-3.1.2A E2022-3.1.5AV E2022-1.1ASL |
CPE
Remediation
| |
| GX Earth 1010 | E1010-1.1ASL |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion