CVE-2018-10561
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Dasan GPON Routers Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life and should be disconnected if still in use.
תיאור (מקור, אנגלית)
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 92% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-287
מוצרים מושפעים
dasannetworks: gpon router firmware; dasannetworks: gpon router
קישורים
- https://www.exploit-db.com/exploits/44576/ ExploitThird Party AdvisoryVDB Entry
- https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ ExploitTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/44576/ ExploitThird Party AdvisoryVDB Entry
- https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ ExploitTechnical DescriptionThird Party Advisory
- http://www.securityfocus.com/bid/107053 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/107053 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource