CVE-2018-10561
CRITICAL(9.8)KEVLikely Exploited
Dasan GPON Routers Authentication Bypass Vulnerability
Description
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| dasannetworks | gpon router firmware | - |
Multiple CVSS Assessments
Source: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://www.securityfocus.com/bid/107053(Broken Link, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/44576/(Exploit, Third Party Advisory, VDB Entry)
- https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/(Exploit, Technical Description, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-10561(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.