Description
A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was discovered in the utilities_configurationsave.cgi component of Calix GigaSpire 26.1.0. Manipulating the sessionKey argument can cause the web management interface to crash, resulting in a denial of service. The flaw is exploitable from a remote location and a published exploit is available.

Affected Systems

The vulnerability affects Calix GigaSpire devices running firmware version 26.1.0. No other product or version information is available.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available, so the contemporary exploitation likelihood is unclear, but the existence of a published exploit and remote attack capability increase concern. The issue is not listed in the CISA KEV catalog. Attackers would remotely trigger the flaw by sending a crafted request to utilities_configurationsave.cgi with a manipulated sessionKey value, causing the service to become unavailable.

Generated by OpenCVE AI on August 13, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Calix’s website or vendor support for an updated firmware or patch that addresses the sessionKey handling issue.
  • If a patch is not available, restrict access to the Web Management Interface to trusted IP addresses or use a firewall to limit exposure.
  • Configure the device to use secure authentication, ensuring session keys are validated for length and format, and consider disabling unused web management features to reduce the attack surface.

Generated by OpenCVE AI on August 13, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
First Time appeared Calix
Calix gigaspire
Weaknesses CWE-404
CPEs cpe:2.3:a:calix:gigaspire:*:*:*:*:*:*:*:*
Vendors & Products Calix
Calix gigaspire
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T16:40:19.435Z

Reserved: 2026-08-13T14:25:09.687Z

Link: CVE-2026-19745

cve-icon Vulnrichment

Updated: 2026-08-14T16:40:13.642Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T20:17:21.203

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-19745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:30:54Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release