Sceawere
Vulnerability Detail
CVE-2026-19745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Calix GigaSpire Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- Calix
- Product
- GigaSpire
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-08-13T20:17:21.203Z",
"pubdate": "2026-08-13T20:17:21.203Z",
"executiveSummary": "A denial of service vulnerability has been identified within the Web Management Interface of the Calix GigaSpire 26.1.0 platform.\nThe security defect resides in the utilities_configurationsave.cgi file and is triggered via improper handling of the sessionKey argument.\nA remote, unauthenticated attacker can exploit this flaw to cause a denial of service condition on the targeted device, severely impacting availability.\nPublic exploits are currently available for this vulnerability, elevating the operational risk to deployed environments.\nThe vendor was notified of the disclosure prior to publication but failed to provide a response or remediation plan.\nOrganizations utilizing the affected Calix GigaSpire version must implement immediate compensating controls to restrict exposure of the web management interface.",
"technicalDetails": "The vulnerability affects the Web Management Interface of Calix GigaSpire version 26.1.0, specifically targeting the CGI script located at utilities_configurationsave.cgi.\nThe root cause stems from insecure input validation and parameter parsing within an unknown underlying function that processes the sessionKey argument.\nAn unauthenticated remote attacker can craft and transmit a malicious HTTP request containing a manipulated sessionKey parameter directly to the vulnerable endpoint.\nUpon receiving the malformed or manipulated argument, the application logic fails to safely handle the input, resulting in an exception, resource exhaustion, or application crash.\nThis execution flow leads directly to a denial of service state, rendering the device management capabilities and potentially network routing functions unresponsive.\nThe attack vector is network-exposed, allowing remote exploitation over the network without requiring prior authentication or privileged access levels.\nDue to the public availability of exploit material, threat actors can readily automate the delivery of the malicious payload to disrupt targeted devices.\nPost-exploitation impact is constrained to availability degradation, specifically causing service disruption on the management plane of the affected Calix GigaSpire unit."
}