An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
Is CVE-2018-10561 exploited?
Listed in the CISA KEV catalog on 2022-03-31.
Federal remediation due 2022-04-21.
Past that date by 1577 days.
EPSS puts exploitation in the next 30 days at 93%.
Public exploit code: proof of concept.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2018-10561
PlainSec has not published a story about this CVE.