PT-2025-36961 · Calix+1 · Calix Gigacenter 844E+4

Danilo Erazo

+1

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-54084

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Calix GigaCenter ONT versions 844E Calix GigaCenter ONT versions 844G Calix GigaCenter ONT versions 844GE Calix GigaCenter ONT versions 854GE
Description: An OS Command Injection issue exists in Calix GigaCenter ONT (Quantenna SoC modules). Authenticated attackers possessing 'super' user credentials can execute arbitrary OS commands due to improper input validation, potentially leading to full system compromise.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54084

Affected Products

Calix Gigacenter 844E
Calix Gigacenter 844G
Calix Gigacenter 844Ge
Calix Gigacenter 854Ge
Quantenna Soc Modules