CVE-2025-34049

CRITICAL EXPLOITED

OptiLink ONT1GEW GPON <V2.1.11_X101 Build 1127.190306 - Command Inj...

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-34049 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including SecNigma.

AI-analyzed exploit summary This exploit targets an authenticated remote code execution vulnerability in OptiLink ONT1GEW GPON routers (Build 1127.190306). It leverages command injection in the formTracert endpoint to execute a reverse shell via mknod and netcat, bypassing the lack of mkfifo in the BusyBox environment.

Description

An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails to properly sanitize user input in the target_addr parameter of the formTracert and formPing administrative endpoints. An authenticated attacker can inject arbitrary operating system commands, which are executed with root privileges, leading to remote code execution. Successful exploitation enables full compromise of the device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

Exploits (1)

exploitdb WORKING POC
by SecNigma · pythonwebappshardware
https://www.exploit-db.com/exploits/49955

This exploit targets an authenticated remote code execution vulnerability in OptiLink ONT1GEW GPON routers (Build 1127.190306). It leverages command injection in the formTracert endpoint to execute a reverse shell via mknod and netcat, bypassing the lack of mkfifo in the BusyBox environment.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306
Auth required
Prerequisites: Network access to the target router · Valid credentials (default or backdoor: e8c:e8c) · Netcat listener on attacker's machine
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Various Sources product
https://optilinknetwork.com/
Third Party Advisory third-party-advisory
https://vulncheck.com/advisories/optilink-ont1gew-router-rce
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/49955

Scores

CVSS v4 9.4
EPSS 0.0059
EPSS Percentile 69.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-06-26
CWE
CWE-78
Status published
Products (1)
OptiLink/ONT1GEW GPON < V2.1.11_X101 Build 1127.190306
Published Jun 26, 2025
Tracked Since Feb 18, 2026