CVE-2026-45433
Deferred
Deferred - Pending Action
Hardcoded RSA Private Key in GX Earth 2022 ONT
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gx_earth | gx_earth | 2022 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |