CVE-2021-40113
CRITICALCisco Catalyst Pon Switch Cgp-ont-1p ... - Improper Access Control
Title source: ruleDescription
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
Exploits (1)
Scores
CVSS v3
10.0
EPSS
0.1367
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
CWE-78
Status
published
Products (5)
cisco/catalyst_pon_switch_cgp-ont-1p_firmware
< 1.1.1.14
cisco/catalyst_pon_switch_cgp-ont-4p_firmware
< 1.1.3.17
cisco/catalyst_pon_switch_cgp-ont-4pvc_firmware
< 1.1.3.17
cisco/catalyst_pon_switch_cgp-ont-4pv_firmware
< 1.1.3.17
cisco/catalyst_pon_switch_cgp-ont-4tvcw_firmware
< 1.1.3.17
Published
Nov 04, 2021
Tracked Since
Feb 18, 2026