CVE-2025-63409

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
24/02/2026
Last modified:
26/02/2026

Description

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gcomtw:gcom_epon_1ge_firmware:c00r371v00b01:*:*:*:*:*:*:*
cpe:2.3:h:gcomtw:gcom_epon_1ge:-:*:*:*:*:*:*:*