CVE-2026-45433 Details
Description
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.
A vulnerability exists in GX Earth 2022 ONT models due to a hardcoded RSA private key in the device firmware. This key can be extracted by a remote attacker, potentially allowing the decryption of HTTPS traffic and facilitating Man-in-the-Middle (MITM) attacks on the device.
Users are advised to upgrade GX Earth 2022 to the latest firmware versions E2022-3.1.5A, E2022-3.1.8AV, or E2022-1.2ASL. For GX Earth 1010, the latest firmware version is E1010-1.2ASL.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0288 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GX INDIA GX Earth 2022 | E2022-3.1.2A E2022-3.1.5AV E2022-1.1ASL |
CPE
Remediation
| |
| GX INDIA GX Earth 1010 | E1010-1.1ASL |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion