FiberHome AN5506-01A ONU GPON OS Command Injection Vulnerability in Diagnosis Component

Vulnerability

A critical OS command injection vulnerability has been identified in the FiberHome AN5506-01A ONU GPON RP2511, specifically within the Diagnosis component. The issue arises from the manipulation of the Destination Address argument, allowing remote exploitation of the vulnerability.

Impact

Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the operating system of the affected device.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.