V-SOL GPON/EPON OLT Platform Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in V-SOL GPON/EPON OLT Platform version 2.03. This vulnerability allows attackers to perform administrative actions without the user's consent. By tricking authenticated administrators into visiting a malicious webpage, attackers can create admin users, enable SSH, or alter system settings.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative actions being performed on the affected OLT platform.

Reproduction

To exploit this vulnerability, an attacker must craft a malicious webpage that, when visited by an authenticated administrator, sends a POST request to the OLT's user management or SSH configuration endpoint. The request must include the necessary parameters to add a new admin user or enable SSH, effectively bypassing normal authentication checks.

Added: Dec 24, 2025, 8:33 PM
Updated: Dec 24, 2025, 9:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.