Impact
A flaw was discovered in the utilities_configurationsave.cgi component of Calix GigaSpire 26.1.0. Manipulating the sessionKey argument can cause the web management interface to crash, resulting in a denial of service. The flaw is exploitable from a remote location and a published exploit is available.
Affected Systems
The vulnerability affects Calix GigaSpire devices running firmware version 26.1.0. No other product or version information is available.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, so the contemporary exploitation likelihood is unclear, but the existence of a published exploit and remote attack capability increase concern. The issue is not listed in the CISA KEV catalog. Attackers would remotely trigger the flaw by sending a crafted request to utilities_configurationsave.cgi with a manipulated sessionKey value, causing the service to become unavailable.
OpenCVE Enrichment