CVE-2018-10562: Dasan GPON Routers Command Injection Vulnerability
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the desthost parameter in a diagaction=ping request to a GponForm/diagForm URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
Other sources
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Dasan GPON routers from the network if they are still in use.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-10562?
CVE-2018-10562 is considered a high severity vulnerability due to the potential for command injection.
How do I fix CVE-2018-10562?
To fix CVE-2018-10562, update the firmware of the Dasan Networks GPON router to the latest version provided by the manufacturer.
What types of devices are affected by CVE-2018-10562?
CVE-2018-10562 specifically affects Dasan Networks GPON home routers.
What impact does CVE-2018-10562 have on a network?
Exploitation of CVE-2018-10562 can allow attackers to execute arbitrary commands on the affected router, potentially compromising the network's security.
Are all Dasan GPON routers vulnerable to CVE-2018-10562?
Not all Dasan GPON routers are vulnerable; the vulnerability specifically affects certain firmware versions.