CVE-2026-45433: Gx India Gx Earth 1010
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.
Affected products
- Gx India Gx Earth 1010: version E1010-1.1ASL only
- Gx India Gx Earth 2022: version E2022 - 3.1.2A only; version E2022 - 3.1.5AV only; version E2022 - 1.1ASL only
Published 2026-06-04. Last modified 2026-07-22.