PoC Index

CVE-2018-10561

KEVCRITICAL 9.8EPSS 93.0%

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
93.04% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-31
Published
2018-05-04
Updated
2025-10-21

Proof-of-concept exploits (3)

ExploitDB entries (1)

References

Related