Description
OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
844E (custom)
844G (custom)
844GE (custom)
854GE (custom)
References
fluidattacks.com/advisories/bacalao
www.calix.com
revers3everything.com/calix-case-five-0-days-five-cves/