An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
Is CVE-2018-10562 exploited?
Listed in the CISA KEV catalog on 2022-03-31.
Federal remediation due 2022-04-21.
Past that date by 1577 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 99.9%.
Public exploit code: proof of concept.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2018-10562
PlainSec has not published a story about this CVE.