CVE-2017-18046

CRITICAL EXPLOITED

Dasan GPON ONT H640X 12.02-01121 Buffer Overflow via Long POST Request

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-18046 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi).

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3552
Various Sources x_refsource_misc
https://pastebin.com/Yxd9S46A

Scores

CVSS v3 9.8
EPSS 0.0514
EPSS Percentile 91.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2018-02-12
CWE
CWE-119
Status published
Products (3)
dasannetworks/h640x_firmware 2.77p1-1124
dasannetworks/h640x_firmware 3.03p2-1146
dasannetworks/h640x_firmware 12.02-01121
Published Jan 21, 2018
Tracked Since Feb 18, 2026