peter bassill · operator
$ cve CVE-2021-40113 JSON

CVE-2021-40113

10.0
CRITICAL · CVSS 3.1 · EPSS 4.6% (pctl 91)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS4.63% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2021-11-04
Last modified2026-06-17

Affected (10)

VendorProduct
ciscocatalyst pon switch cgp-ont-1p
ciscocatalyst pon switch cgp-ont-1p firmware
ciscocatalyst pon switch cgp-ont-4p
ciscocatalyst pon switch cgp-ont-4p firmware
ciscocatalyst pon switch cgp-ont-4pv
ciscocatalyst pon switch cgp-ont-4pv firmware
ciscocatalyst pon switch cgp-ont-4pvc
ciscocatalyst pon switch cgp-ont-4pvc firmware
ciscocatalyst pon switch cgp-ont-4tvcw
ciscocatalyst pon switch cgp-ont-4tvcw firmware

References

→ the Explorer  ·  watch your stack  ·  NVD