CVE-2018-10561
CRITICAL(9.8)KEVWahrscheinlich ausgenutzt
Dasan GPON Routers Authentication Bypass Vulnerability
Beschreibung
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| dasannetworks | gpon router firmware | - |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Referenzen
- http://www.securityfocus.com/bid/107053(Broken Link, Third Party Advisory, VDB Entry)
- https://www.exploit-db.com/exploits/44576/(Exploit, Third Party Advisory, VDB Entry)
- https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/(Exploit, Technical Description, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-10561(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.