Executive brief
Dasan GPON home routers contain an authentication bypass vulnerability that allows an attacker to gain unauthorized management access by appending '?images' to URLs requiring authentication. This flaw is frequently chained with CVE-2018-10562 to achieve remote code execution.
Affected products
- Dasan Networks GPON home routers All versions (End-of-Life)
Timeline
- 2018-05-03: disclosed: NVD Published Date
- 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-21: other: CISA Due Date for remediation (disconnect EOL devices)