Description
A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in an unidentified function of the traceroute.cmd file in Calix GigaSpire 26.1.0 allows an attacker to trigger a denial of service. The vulnerability is exploitable remotely, and a public exploit has already been disclosed. It is a moderate severity flaw, with a CVSS score of 5.3, and is categorized as CWE‑404 – Improper Handling of Unspecified or Unknown Error. The impact is a loss of service availability for the affected device; no compromise of confidentiality or integrity has been reported, and we infer that the vulnerability does not impact these vectors.

Affected Systems

Devices running Calix GigaSpire firmware version 26.1.0 are affected. The issue is confined to the traceroute.cmd component of the firmware package shipped by Calix. No other versions or model variants are listed as vulnerable.

Risk and Exploitability

The CVSS score indicates moderate risk; however, because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the exploitation likelihood is not well quantified. The attack can be launched from the outside, where an adversary crafts traffic that triggers the vulnerable function. Successful execution leads to service interruption of the GigaSpire unit, which could affect network availability for customers relying on that device. No known mitigations or patch releases are yet available from the vendor.

Generated by OpenCVE AI on August 13, 2026 at 21:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest firmware release that updates the traceroute.cmd code to include proper error handling, addressing the CWE‑404 issue.
  • If an upgrade is not possible, isolate the device by restricting remote access to its management interfaces so that only trusted internal networks can reach the traceroute.cmd endpoint.
  • Implement network-level rate limiting or monitoring on traffic that invokes traceroute.cmd to detect and throttle repeated attempts potentially linked to the DoS attack.

Generated by OpenCVE AI on August 13, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Calix GigaSpire traceroute.cmd denial of service
First Time appeared Calix
Calix gigaspire
Weaknesses CWE-404
CPEs cpe:2.3:a:calix:gigaspire:*:*:*:*:*:*:*:*
Vendors & Products Calix
Calix gigaspire
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-13T19:26:06.261Z

Reserved: 2026-08-13T14:25:14.108Z

Link: CVE-2026-19746

cve-icon Vulnrichment

Updated: 2026-08-13T19:25:23.855Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T20:17:21.380

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-19746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:30:45Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release