Junglewise Threat Intelligence

CVE-2018-10562: Dasan GPON Routers Command Injection Vulnerability

CVE-2018-10562 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-31

Executive brief

Dasan GPON home routers are vulnerable to OS command injection via the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI. An attacker can execute arbitrary commands and retrieve output because the device saves ping results to a publicly accessible temporary file.

Affected products

  • Dasan Networks GPON Router All versions (End-of-Life)

Timeline

  • 2018-05-03: disclosed: NVD Published Date
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats