CVE-2025-7635

Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
References
Link Resource
https://fluidattacks.com/advisories/sal Exploit Mitigation Third Party Advisory
https://revers3everything.com/calix-case-five-0-days-five-cves/ Third Party Advisory
https://www.calix.com Product
https://fluidattacks.com/advisories/sal Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:calix:calix_gigacenter_ont:*:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:844e:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:844g:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:844ge:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:854ge:*:*:*:*:*:*:*

History

22 Dec 2025, 20:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
First Time Calix calix Gigacenter Ont
Calix
CPE cpe:2.3:a:calix:calix_gigacenter_ont:844e:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:844ge:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:844g:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:*:*:*:*:*:*:*:*
cpe:2.3:a:calix:calix_gigacenter_ont:854ge:*:*:*:*:*:*:*
References () https://fluidattacks.com/advisories/sal - () https://fluidattacks.com/advisories/sal - Exploit, Mitigation, Third Party Advisory
References () https://revers3everything.com/calix-case-five-0-days-five-cves/ - () https://revers3everything.com/calix-case-five-0-days-five-cves/ - Third Party Advisory
References () https://www.calix.com - () https://www.calix.com - Product

12 Sep 2025, 14:15

Type Values Removed Values Added
References
  • () https://revers3everything.com/calix-case-five-0-days-five-cves/ -

10 Sep 2025, 14:15

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/sal - () https://fluidattacks.com/advisories/sal -

09 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-09 20:15

Updated : 2025-12-22 20:01


NVD link : CVE-2025-7635

Mitre link : CVE-2025-7635

CVE.ORG link : CVE-2025-7635


JSON object : View

Products Affected

calix

  • calix_gigacenter_ont
CWE
CWE-306

Missing Authentication for Critical Function