HIGH · 8.8

CVE-2025-63409

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

Vulnerability Description

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GcomtwGcom Epon 1Ge Firmwarec00r371v00b01
GcomtwGcom Epon 1Ge-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-63409?

CVE-2025-63409 is a vulnerability with a CVSS score of 8.8 (HIGH). Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

How severe is CVE-2025-63409?

CVE-2025-63409 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-63409?

Check the references section above for vendor advisories and patch information. Affected products include: Gcomtw Gcom Epon 1Ge Firmware, Gcomtw Gcom Epon 1Ge.