Executive brief
Dasan GPON home routers are vulnerable to OS command injection via the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI. An attacker can execute arbitrary commands and retrieve output because the device saves ping results to a publicly accessible temporary file.
Affected products
- Dasan Networks GPON Router All versions (End-of-Life)
Timeline
- 2018-05-03: disclosed: NVD Published Date
- 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog