Description
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.
Problem types
CWE-321 Use of hard-coded cryptographic key
Product status
version E2022 - 3.1.2A
version E2022 - 3.1.5AV
version E2022 - 1.1ASL
version E1010-1.1ASL
Credits
This vulnerability is reported by Anmol Bakshi.
References
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2026-0288