Vulnerability Description
Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.szgcom.com
- https://github.com/theShinigami/CVE-Disclosures/blob/main/CVE-2025-71056/README.
- https://johnbai.en.made-in-china.com/product/JXnENzmlJFpv/China-H18gn-Series-Gpo
FAQ
What is CVE-2025-71056?
CVE-2025-71056 is a vulnerability with a CVSS score of 8.1 (HIGH). Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
How severe is CVE-2025-71056?
CVE-2025-71056 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71056?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.