PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45431 GX INDIA CVE debrief

CVE-2026-45431 is a HIGH severity vulnerability in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device. Successful exploitation of this vulnerability could allow the attacker to perform remote code execution with root privileges on the targeted device. The CVSS score for this vulnerability is 8.7.

Vendor
GX INDIA
Product
GX Earth 2022
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-04
Original CVE updated
2026-06-04
Advisory published
2026-06-04
Advisory updated
2026-06-04

Who should care

Administrators and users of GX Earth ONT models should be aware of this vulnerability and take necessary actions to mitigate it.

Technical summary

The vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. This allows an authenticated remote attacker to inject arbitrary and execute OS commands on the targeted device, leading to remote code execution with root privileges.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches or updates provided by the vendor to fix the vulnerability.
  • Restrict access to the web management interface to authorized personnel only.
  • Monitor the device for suspicious activity and implement additional security measures to detect and prevent exploitation.

Evidence notes

The CVE record was published on 2026-06-04T12:16:26.110Z and modified on 2026-06-04T15:26:10.707Z. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity.

Official resources

CVE-2026-45431 was published on 2026-06-04T12:16:26.110Z.