CVE-2018-10562: Dasan GPON Routers Command Injection Vulnerability

Published May 4, 2018
·
Updated

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the desthost parameter in a diagaction=ping request to a GponForm/diagForm URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

Other sources

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

CISA

Affected Software

5 affected components
Dasannetworks Gpon Router Firmware
Dasannetworks Gpon Router
Dasan Gigabit Passive Optical Network (GPON) Routers
All of the following
Dasannetworks Gpon Router Firmware
Dasannetworks Gpon Router

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Disconnect Dasan Networks GPON routers from all networks if still in use (device is end-of-life). Isolate affected devices from the Internet and internal networks until they can be replaced or fully decommissioned.

  2. Compensating control

    Block access to the management/diagnostics endpoints and parameters that enable the vulnerability: deny or firewall HTTP(S) requests to GponForm/diag_Form and /diag.html, and block requests containing diag_action=ping with a dest_host parameter. Additionally restrict access to the router management interface to trusted IP addresses only (management-plane ACLs/WAF rules).

Event History

May 4, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Mar 31, 2022
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Jan 29, 2025
News Published
via The Register·03:32 PM
News Published
via The Register·03:36 PM
Jan 30, 2025
News Published
via BleepingComputer·12:55 AM
News Published
via BleepingComputer·12:57 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-10562?

CVE-2018-10562 is considered a high severity vulnerability due to the potential for command injection.

2

How do I fix CVE-2018-10562?

To fix CVE-2018-10562, update the firmware of the Dasan Networks GPON router to the latest version provided by the manufacturer.

3

What types of devices are affected by CVE-2018-10562?

CVE-2018-10562 specifically affects Dasan Networks GPON home routers.

4

What impact does CVE-2018-10562 have on a network?

Exploitation of CVE-2018-10562 can allow attackers to execute arbitrary commands on the affected router, potentially compromising the network's security.

5

Are all Dasan GPON routers vulnerable to CVE-2018-10562?

Not all Dasan GPON routers are vulnerable; the vulnerability specifically affects certain firmware versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203