CVE-2025-54084: Calix Gigacenter Ont

High severity, CVSS 8.5. EPSS: 0.8% chance of exploitation in the next 30 days.

OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

Affected products

  • Calix Gigacenter Ont: version 844E only; version 844G only; version 844GE only; version 854GE only

Published 2025-09-09. Last modified 2026-06-17.