PT-2025-26998 · Unknown · Optilink Ont1Gew
Amal
+1
·
Published
2025-06-26
·
Updated
2025-12-31
·
CVE-2025-34049
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
OptiLink ONT1GEW GPON router firmware versions prior to V2.1.11 X101 Build 1127.190306
Description:
An OS command injection issue exists due to the router's web management interface failing to properly sanitize user input in the
target addr parameter of the "formTracert" and "formPing" administrative endpoints. This allows an authenticated attacker to inject arbitrary operating system commands, which are executed with root privileges, leading to remote code execution. Successful exploitation enables full compromise of the device.Recommendations:
For OptiLink ONT1GEW GPON router firmware versions prior to V2.1.11 X101 Build 1127.190306, consider disabling the "formTracert" and "formPing" administrative endpoints as a temporary workaround until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using the
target addr parameter in the affected endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Optilink Ont1Gew