Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5h68-jg5g-w367

Опубликовано: 04 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.

EPSS

Процентиль: 27%
0.00344
Низкий

8.7 High

CVSS4

Дефекты

CWE-321

Связанные уязвимости

nvd
2 месяца назад

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.

EPSS

Процентиль: 27%
0.00344
Низкий

8.7 High

CVSS4

Дефекты

CWE-321