60
CVE-2021-40112
—CVSS 3.1
7.5 high
EPSS
1%p71
Published
()
Modified
Description
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
- Vendors
- cisco
- Products
- catalyst pon switch cgp-ont-1p firmware, catalyst pon switch cgp-ont-4p firmware, catalyst pon switch cgp-ont-4pvc firmware, catalyst pon switch cgp-ont-4tvcw firmware, catalyst pon switch cgp-ont-4pv firmware
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N