PT-2026-21553 · Gcom · Gcom Epon 1Ge Onu

Published

2026-02-23

·

Updated

2026-02-28

·

CVE-2025-71056

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GCOM EPON 1GE ONU version C00R371V00B01
Description The software suffers from improper session management, which enables attackers to hijack user sessions. This is achieved by spoofing the IP address of an authenticated user.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-71056

Affected Products

Gcom Epon 1Ge Onu