Impact
A flaw in an unidentified function of the traceroute.cmd file in Calix GigaSpire 26.1.0 allows an attacker to trigger a denial of service. The vulnerability is exploitable remotely, and a public exploit has already been disclosed. It is a moderate severity flaw, with a CVSS score of 5.3, and is categorized as CWE‑404 – Improper Handling of Unspecified or Unknown Error. The impact is a loss of service availability for the affected device; no compromise of confidentiality or integrity has been reported, and we infer that the vulnerability does not impact these vectors.
Affected Systems
Devices running Calix GigaSpire firmware version 26.1.0 are affected. The issue is confined to the traceroute.cmd component of the firmware package shipped by Calix. No other versions or model variants are listed as vulnerable.
Risk and Exploitability
The CVSS score indicates moderate risk; however, because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the exploitation likelihood is not well quantified. The attack can be launched from the outside, where an adversary crafts traffic that triggers the vulnerable function. Successful execution leads to service interruption of the GigaSpire unit, which could affect network availability for customers relying on that device. No known mitigations or patch releases are yet available from the vendor.
OpenCVE Enrichment