Junglewise Threat Intelligence

CVE-2018-10561: Dasan GPON Routers Authentication Bypass Vulnerability

CVE-2018-10561 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-31

Executive brief

Dasan GPON home routers contain an authentication bypass vulnerability that allows an attacker to gain unauthorized management access by appending '?images' to URLs requiring authentication. This flaw is frequently chained with CVE-2018-10562 to achieve remote code execution.

Affected products

  • Dasan Networks GPON home routers All versions (End-of-Life)

Timeline

  • 2018-05-03: disclosed: NVD Published Date
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-21: other: CISA Due Date for remediation (disconnect EOL devices)

Related threats