ZeroHour

CVE-2018-10561

KEV PoC ×2mass

Authentication Bypass in Dasan GPON Home Routers (CVE-2018-10561)

CISA: Dasan GPON Routers Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

CVE-2018-10561 is a critical authentication bypass (CWE-287, CVSS 9.8) in Dasan GPON home router firmware: the devices fail to properly enforce login when a specific suffix is added to a URL. An attacker simply appends "?images" to any protected URL — for example /menu.html?images/ or /GponForm/diag_FORM?images/ — and the router treats the request as already authenticated. Once bypassed, the attacker gains full access to the device's management interface, enabling configuration changes, diagnostics, and use of the router as a botnet node or network pivot. All Dasan Gigabit Passive Optical Network (GPON) routers running the affected firmware are exposed, especially units with their web interface reachable from the internet; CISA notes the impacted product is end-of-life. Exploitation is active and widespread: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-31), carries a 92.9% EPSS probability of exploitation within 30 days, and IoT botnets have historically targeted these routers.

What to do: CISA's required action is to disconnect or replace these routers if still in use, since the product is end-of-life and should not remain deployed. As an interim mitigation, remove the device's web management interface from internet exposure and block or strip requests containing "?images"; verify exposure by loading /menu.html?images/ without logging in — if it returns the management page, the device is vulnerable. A community mitigation tool and unofficial patch have been published by researchers, but replacement remains the recommended fix, and defenders should expect continued botnet scanning of exposed units.

Affected
Dasan Networks GPON home router firmware (Dasan Gigabit Passive Optical Network Routers)
Estimated exposure
massseveral hundred thousand internet-exposed routers (10^5-10^6 range) — These GPON home routers were mass-deployed by ISPs, and internet-wide scans published around the 2018 disclosure (the VPNMentor research cited among the PoC references) identified on the order of hundreds of thousands of exposed devices,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

CISA Known Exploited Vulnerability
Affected
Dasan Gigabit Passive Optical Network (GPON) Routers
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dasannetworks
Products
gpon router firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news