VYPR
Vendor

Calix

Products
5
CVEs
7
Across products
10
Status
Private

Products

5

Recent CVEs

7
  • CVE-2025-54084HigSep 9, 2025
    risk 0.55cvss epss 0.01

    OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This…

  • CVE-2025-7635HigSep 9, 2025
    risk 0.50cvss 7.7epss 0.00

    Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

  • CVE-2025-53914HigSep 9, 2025
    risk 0.46cvss epss 0.00

    Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

  • CVE-2025-53913HigSep 9, 2025
    risk 0.46cvss epss 0.00

    Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

  • CVE-2025-54083MedSep 9, 2025
    risk 0.33cvss epss 0.00

    Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

  • CVE-2026-19746MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…

  • CVE-2026-19745MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched…