nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1616 CVE-2025-1616
MEDIUM
FiberHome AN5506-01A ONU GPON Diagnosis os command injection
Record summary
CVE-2025-1616 has a selected CVSS score of 5.1 (medium).
Description
A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AN5506-01A ONU GPONBrowse FiberHome / AN5506-01A ONU GPON | CVE List | RP2511 | affected |
References
4VDB-296606 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.296606 VDB-296606 | FiberHome AN5506-01A ONU GPON Diagnosis os command injectionvdb entryTechnical description
https://vuldb.com/?id.296606 Submit #501483 | FiberHome AN5506-01-A RP2511 Command InjectionThird-party advisory
https://vuldb.com/?submit.501483