CVE-2025-54084 HIGH

CVE-2025-54084: Calix Gigacenter ONT - Command Injection

Vendor Calix
Product GigaCenter ONT
Weakness CWE-78
Published September 9, 2025
Last update September 12, 2025

CVSS base score

8.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

Key dates

02Disclosure timeline

September 9, 2025 CVE published
September 12, 2025 Record updated