Denial of Service Vulnerability in Calix GigaSpire Web Management Interface
CVE-2026-19745

5.3MEDIUM

Key Information:

Vendor

Calix

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-19745?

A security flaw has been identified in the Calix GigaSpire version 26.1.0, specifically within the web management interface's utilities_configurationsave.cgi file. This vulnerability can be exploited by manipulating the sessionKey argument, potentially leading to a denial of service condition. The nature of this flaw allows attackers to launch remote exploits. It is crucial for users and administrators to be aware of its existence, especially since the vendor has not provided an official response to the disclosure.

Affected Version(s)

GigaSpire 26.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VulDB CNA Team
.