Sceawere

Vulnerability Detail

CVE-2026-19746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Calix GigaSpire Traceroute Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Calix
Product
GigaSpire
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-13T20:17:21.380Z",
  "pubdate": "2026-08-13T20:17:21.380Z",
  "executiveSummary": "A denial of service vulnerability has been identified in Calix GigaSpire version 26.1.0, specifically within an undocumented function residing in the traceroute.cmd file.\nThe vulnerability allows remote attackers to induce a denial of service condition on the targeted device, rendering the affected functionality or system unavailable.\nThe flaw stems from improper handling of inputs or execution states within the vulnerable script or underlying binary executed via traceroute.cmd.\nPublic disclosure of the exploit increases the risk of active targeting by malicious actors.\nThe vendor was contacted regarding this vulnerability disclosure but failed to provide any response or official remediation guidance.\nAttackers can initiate the exploitation sequence remotely without requiring prior authentication or privileged access, depending on the network exposure of the management or diagnostic interfaces.\nRisk implications include service degradation, loss of remote manageability, and potential localized network disruption for deployments utilizing the affected Calix GigaSpire firmware version.",
  "technicalDetails": "The vulnerability resides in the Calix GigaSpire firmware version 26.1.0, specifically targeting an unknown function within the traceroute.cmd file.\nWhile the exact implementation details of the vulnerable function remain unspecified in public disclosures, the involvement of traceroute.cmd strongly suggests that network diagnostic routines or command-line wrappers are improperly parsing or handling parameters.\nThe root cause is characteristic of inadequate input validation, resource exhaustion, or improper exception handling when processing malformed or malicious inputs passed to the diagnostic subsystem.\nAttack vector and network exposure: The vulnerability can be exploited remotely, indicating that the vulnerable endpoint is accessible either via wide-area management interfaces, local network services, or exposed diagnostic daemons running on the device.\nAuthentication and privilege requirements: The exploitation vector does not explicitly require user authentication or specialized administrative privileges, lowering the barrier to entry for remote threat actors.\nAttack flow and payload behavior: 1. The remote attacker identifies the target Calix GigaSpire device running version 26.1.0 and locates the interface or API associated with traceroute functionality. 2. The attacker crafts a specialized payload or malformed request designed to trigger the vulnerable function within traceroute.cmd. 3. Upon receiving the input, the underlying script or application fails to gracefully handle the parameters, leading to a system crash, process termination, resource lockup, or kernel panic. 4. This anomalous execution state results in a denial of service, disrupting normal networking operations and administrative access.\nPost-exploitation impact: The immediate impact is limited to denial of service, causing device unresponsiveness that typically requires a physical power cycle or hardware reset to recover, assuming the crash condition is non-persistent in non-volatile memory."
}
CVE-2026-19746: Calix GigaSpire Traceroute Denial of Service (MEDIUM Severity, CVSS: 4.3) - Sceawere