CVE-2018-10561
KEVCRITICAL 9.8EPSS 93.0%
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 93.04% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-31
- Published
- 2018-05-04
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- ATpiu/CVE-2018-105623★ · 2018-06-07
- Truongnn92/GPON0★ · 2018-07-19
- ethicalhackeragnidhra/GPON4★ · 2018-05-17