Sceawere

Vulnerability Detail

CVE-2026-19745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Calix GigaSpire Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Calix
Product
GigaSpire
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-13T20:17:21.203Z",
  "pubdate": "2026-08-13T20:17:21.203Z",
  "executiveSummary": "A denial of service vulnerability has been identified within the Web Management Interface of the Calix GigaSpire 26.1.0 platform.\nThe security defect resides in the utilities_configurationsave.cgi file and is triggered via improper handling of the sessionKey argument.\nA remote, unauthenticated attacker can exploit this flaw to cause a denial of service condition on the targeted device, severely impacting availability.\nPublic exploits are currently available for this vulnerability, elevating the operational risk to deployed environments.\nThe vendor was notified of the disclosure prior to publication but failed to provide a response or remediation plan.\nOrganizations utilizing the affected Calix GigaSpire version must implement immediate compensating controls to restrict exposure of the web management interface.",
  "technicalDetails": "The vulnerability affects the Web Management Interface of Calix GigaSpire version 26.1.0, specifically targeting the CGI script located at utilities_configurationsave.cgi.\nThe root cause stems from insecure input validation and parameter parsing within an unknown underlying function that processes the sessionKey argument.\nAn unauthenticated remote attacker can craft and transmit a malicious HTTP request containing a manipulated sessionKey parameter directly to the vulnerable endpoint.\nUpon receiving the malformed or manipulated argument, the application logic fails to safely handle the input, resulting in an exception, resource exhaustion, or application crash.\nThis execution flow leads directly to a denial of service state, rendering the device management capabilities and potentially network routing functions unresponsive.\nThe attack vector is network-exposed, allowing remote exploitation over the network without requiring prior authentication or privileged access levels.\nDue to the public availability of exploit material, threat actors can readily automate the delivery of the malicious payload to disrupt targeted devices.\nPost-exploitation impact is constrained to availability degradation, specifically causing service disruption on the management plane of the affected Calix GigaSpire unit."
}
CVE-2026-19745: Calix GigaSpire Denial of Service (MEDIUM Severity, CVSS: 4.3) - Sceawere