CVE-2026-55637: genieacs-mcp DNS rebinding vulnerability
genieacs-mcp versions prior to 0.3.2 create an unauthenticated HTTP listener on 127.0.0.1:8080 that does not validate Host or Origin headers, allowing DNS rebinding attacks to expose or modify CPE management state through GenieACS operations.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Successful exploitation can expose or modify CPE management state including device reboots, firmware tasks, TR-069 parameter changes, presets, provisions, tags, connection requests, and task operations.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55637
