CVE-2018-10561: Dasan GPON Routers Authentication Bypass Vulnerability
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diagFORM?images/ URI. One can then manage the device.
Other sources
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Dasan Networks GPON Router devices from all networks (isolate/remove network connectivity, including Internet and internal LAN access) if still in use, because the product is end-of-life and contains an authentication bypass via appending "?images" to device URIs.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-10561?
CVE-2018-10561 is classified as a critical vulnerability due to its potential to allow unauthorized access to the device.
How do I fix CVE-2018-10561?
To fix CVE-2018-10561, update the Dasan GPON router firmware to the latest version provided by the vendor.
What devices are affected by CVE-2018-10561?
CVE-2018-10561 affects Dasan Networks GPON routers that have the vulnerable firmware installed.
How does CVE-2018-10561 impact device security?
CVE-2018-10561 impacts device security by allowing attackers to bypass authentication, gaining unauthorized access to device controls.
What is the exploit method for CVE-2018-10561?
The exploit method for CVE-2018-10561 involves appending '?images' to URLs that require authentication to access the router's management interface.