OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://fluidattacks.com/advisories/bacalao |
![]() ![]() |
https://www.calix.com |
![]() ![]() |
History
Tue, 09 Sep 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE. | |
Title | Calix Gigacenter ONT - Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-09-09T20:37:28.023Z
Reserved: 2025-07-16T15:11:01.685Z
Link: CVE-2025-54084

No data.

Status : Received
Published: 2025-09-09T21:15:36.657
Modified: 2025-09-09T21:15:36.657
Link: CVE-2025-54084

No data.

No data.