First published: Thu Apr 11 2019(Updated: )
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm | ||
All of | ||
Dasannetworks H660rm Firmware | =1.03-0022 | |
Dasannetworks H660rm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9974 is considered a medium severity vulnerability due to the lack of authorization checks, allowing remote command execution.
To fix CVE-2019-9974, you should upgrade the firmware of your DASAN H660RM router to a version that includes security patches.
CVE-2019-9974 can be exploited to execute ping commands to enumerate LAN devices or perform denial of service attacks that may crash the router.
CVE-2019-9974 specifically affects DASAN H660RM routers running firmware version 1.03-0022.
CVE-2019-9974 can be exploited by remote attackers without authentication, making it accessible to anyone on the network.