CVE-2025-54084
HIGH 8.5EPSS 0.8%
OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
- CVSS v4.0
- 8.5 HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS
- 0.80% chance of exploitation in the next 30 days, 54th percentile
- Published
- 2025-09-09
- Updated
- 2025-09-12
Proof-of-concept exploits (1)
- revers3everything/rce-calix-gigacenter4★ · 2025-09-10