CVE-2017-18046
CRITICAL EXPLOITEDDasan GPON ONT H640X 12.02-01121 Buffer Overflow via Long POST Request
Title source: llmExploitation Summary
CVE-2017-18046 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi).
References (3)
Core 3
Core References
Various Sources x_refsource_misc
https://twitter.com/ankit_anubhav/status/982261670394249216
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3552
Various Sources x_refsource_misc
https://pastebin.com/Yxd9S46A
Scores
CVSS v3
9.8
EPSS
0.0514
EPSS Percentile
91.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2018-02-12
CWE
CWE-119
Status
published
Products (3)
dasannetworks/h640x_firmware
2.77p1-1124
dasannetworks/h640x_firmware
3.03p2-1146
dasannetworks/h640x_firmware
12.02-01121
Published
Jan 21, 2018
Tracked Since
Feb 18, 2026