Record summary

CVE-2018-10561 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit. CISA lists CVE-2018-10561 in KEV; VulnCheck reports CVE-2018-10561 use in known ransomware campaigns.

Description

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 31, 2022 · CISA
VulnCheck KEV
Listed · May 7, 2018 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Gigabit Passive Optical Network (GPON) Routers

Browse Dasan / Gigabit Passive Optical Network (GPON) Routers
CISAVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBGPON Routers - Authentication Bypass / Command InjectionExploitDB exploitby vpnmentorNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5