A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI interface but deactivates also Linux Shell, WebGUI and Physical Serial Console access. No confirmation is asked at deactivation time. Loosing access to these services device administrators are at risk of completely loosing device control.
History

Wed, 02 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 14:00:00 +0000

Type Values Removed Values Added
Description A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI interface but deactivates also Linux Shell, WebGUI and Physical Serial Console access. No confirmation is asked at deactivation time. Loosing access to these services device administrators are at risk of completely loosing device control.
Title Improper Access Control Granularity impacting Infinera G42
Weaknesses CWE-1220
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published: 2025-07-02T13:42:42.068Z

Updated: 2025-07-02T20:22:57.416Z

Reserved: 2025-02-18T06:59:55.889Z

Link: CVE-2025-27026

cve-icon Vulnrichment

Updated: 2025-07-02T20:22:54.142Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T14:15:23.900

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-27026

cve-icon Redhat

No data.