8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.
AI Analysis
Hardcoded RSA private key in GX Earth 2022 firmware allows remote attackers to decrypt HTTPS traffic and perform Man-in-the-Middle attacks
Basic Information
ID
CVE-2026-45433
Source
CERT-In
Published
Jun 4, 2026 at 12:13
Modified
Jun 4, 2026 at 13:47
Affected Product
Vendor
GX INDIA
Product
GX Earth 2022
Version
version E2022 - 3.1.2A
Affected Versions
GX INDIA GX Earth 2022 version E2022 - 3.1.2A
GX INDIA GX Earth 2022 version E2022 - 3.1.5AV
GX INDIA GX Earth 2022 version E2022 - 1.1ASL
GX INDIA GX Earth 1010 version E1010-1.1ASL
GX INDIA GX Earth 2022 version E2022 - 3.1.5AV
GX INDIA GX Earth 2022 version E2022 - 1.1ASL
GX INDIA GX Earth 1010 version E1010-1.1ASL
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
GX INDIA
Product
GX Earth 2022
Version
E2022 - 3.1.2A, E2022 - 3.1.5AV, E2022 - 1.1ASL, E1010-1.1ASL