CVE-2019-9974: Critical severity dasan networks h660rm vulnerability
diagtool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9974?
CVE-2019-9974 is considered a medium severity vulnerability due to the lack of authorization checks, allowing remote command execution.
How do I fix CVE-2019-9974?
To fix CVE-2019-9974, you should upgrade the firmware of your DASAN H660RM router to a version that includes security patches.
What types of attacks can be executed using CVE-2019-9974?
CVE-2019-9974 can be exploited to execute ping commands to enumerate LAN devices or perform denial of service attacks that may crash the router.
Which firmware version is affected by CVE-2019-9974?
CVE-2019-9974 specifically affects DASAN H660RM routers running firmware version 1.03-0022.
Who can exploit CVE-2019-9974?
CVE-2019-9974 can be exploited by remote attackers without authentication, making it accessible to anyone on the network.