CVE-2025-71056
Received
Received - Intake
Session Hijacking via IP Spoofing in GCOM EPON ONU
Publication date: 2026-02-23
Last updated on: 2026-02-27
Assigner: MITRE
Description
Description
Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| beijing_huahuan_electronics_co_ltd | gcom_epon | coor371v00b01 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |