CVE-2025-63409
8.8GCOM · EPON 1GE
A privilege escalation vulnerability in GCOM EPON 1GE firmware allows remote authenticated users to modify administrative settings and extract credentials.
Executive summary
A critical privilege escalation flaw in GCOM EPON 1GE firmware allows authenticated attackers to gain full administrative control and extract sensitive credentials.
Vulnerability
This vulnerability involves improper access control and privilege escalation, which allows an authenticated user to bypass authorization checks to modify administrator settings and perform credential extraction.
Business impact
The ability for an authenticated user to extract administrative credentials and modify restricted settings poses a severe risk to network integrity and confidentiality. With a CVSS score of 8.8, this high-severity vulnerability could lead to total compromise of the affected networking hardware, potentially allowing attackers to pivot into internal segments or intercept traffic, resulting in significant operational downtime or data breach.
Remediation
Immediate Action: Restrict management interface access to trusted administrative IP addresses only, and monitor the device for unauthorized configuration changes until a vendor firmware patch is released.
Proactive Monitoring: Review system logs for unusual administrative logins or modification attempts to sensitive configuration parameters.
Compensating Controls: Ensure the device management interface is not exposed to the public internet and use a secure VPN or jump host to manage the device.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists (referenced in the GitHub repository maintained by theShinigami).
Analyst recommendation
Given the potential for complete administrative takeover of the networking equipment, organizations should prioritize isolating these devices from any untrusted network segments immediately. Administrators must monitor for the release of firmware updates from GCOM and apply them as soon as they become available to remediate this improper access control flaw.