CVE-2019-9974

CRITICAL

DASAN H660RM Firmware 1.03-0022 - Unauthenticated Command Execution via diag_tool.cgi

Title source: llm
STIX 2.1

Description

diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.

Scores

CVSS v3 9.1
EPSS 0.0292
EPSS Percentile 85.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-306 CWE-862
Status published
Products (1)
dasannetworks/h660rm_firmware 1.03-0022
Published Apr 11, 2019
Tracked Since Feb 18, 2026