VYPR
Unrated severityNVD Advisory· Published Nov 4, 2021· Updated Nov 7, 2024

Cisco Catalyst PON Series Switches Optical Network Terminal Vulnerabilities

CVE-2021-40112

Description

Multiple vulnerabilities in Cisco Catalyst PON Series ONT web management interface allow unauthenticated remote attackers to log in via default credentials, perform command injection, or modify configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple vulnerabilities in Cisco Catalyst PON Series ONT web management interface allow unauthenticated remote attackers to log in via default credentials, perform command injection, or modify configuration.

Vulnerability

The Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) contains multiple vulnerabilities in its web-based management interface [1]. An unauthenticated, remote attacker could exploit these issues to log in using a default credential if the Telnet protocol is enabled, perform command injection, or modify the device configuration. Affected versions are those running firmware prior to the fixed releases specified in the Cisco advisory [1].

Exploitation

An attacker only needs network access to the affected device's management interface [1]. No authentication is required. By leveraging the default credential (specific details not publicly disclosed), the attacker can gain Telnet access if Telnet is enabled [1]. Alternatively, the attacker can send crafted HTTP requests to the web management interface to perform command injection or configuration modification [1].

Impact

Successful exploitation could allow the attacker to gain unauthorized access to the device with a default credential, execute arbitrary commands on the underlying operating system, or alter the device configuration [1]. This could lead to full compromise of the ONT, enabling interception or disruption of traffic on the passive optical network [1].

Mitigation

Cisco has released free software updates addressing these vulnerabilities [1]. Customers should upgrade to the appropriate fixed version as indicated in the advisory [1]. As a workaround, disabling Telnet and restricting access to the management interface can reduce exposure [1]. No KEV listing is mentioned.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.