CLI Deactivation Vulnerability in Infinera G42 WebGUI
CVE-2025-27026

4.9MEDIUM

Key Information:

Vendor

Infinera

Status
Vendor
CVE Published:
2 July 2025

What is CVE-2025-27026?

The Infinera G42 WebGUI contains a critical missing double-check feature that allows an authenticated administrator to deactivate the CLI, Linux Shell, WebGUI, and Physical Serial Console interfaces without confirmation. This vulnerability puts device administrators at risk by potentially leading to a complete loss of access to essential management interfaces, thereby compromising their ability to control the device. The deactivation process does not prompt for verification, increasing the risk of accidental or malicious lockout.

Affected Version(s)

G42 6.1.3 < 8.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Agenzia per la Cybersicurezza Nazionale
.
CVE-2025-27026 : CLI Deactivation Vulnerability in Infinera G42 WebGUI