CVE-2025-44178

MEDIUM

DASAN GPON ONU H660WM - Info Disclosure

Title source: llm
STIX 2.1

Description

DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to gain unauthorized access to sensitive information and modify its configuration via the UPnP protocol WAN sides without any authentication.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0027
EPSS Percentile 17.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Published Aug 25, 2025
Tracked Since Feb 18, 2026