ZeroHour
Security Affairspublished ()ingested @securityaffairs

Experts released an unofficial patch for Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-10562
+1 in the same advisory: …10561
Unauthenticated RCE in Dasan GPON Routers (CVE-2018-10562)

CVE-2018-10562 is an OS command injection flaw (CWE-78) in the web management interface of Dasan GPON home routers. When chained with the companion authentication bypass CVE-2018-10561, a remote, unauthenticated attacker can send crafted requests that execute arbitrary commands on the device. Successful exploitation yields full control of the router, enabling device takeover, botnet enrollment, and, per CISA, use in ransomware operations. Anyone operating an affected Dasan GPON router — many of which were deployed by internet service providers — is affected, and CISA notes the impacted products are end-of-life. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2022-03-31) with known ransomware use and a 100% EPSS probability of exploitation within 30 days.

Do: Because the product line is end-of-life and CISA's required action is to disconnect impacted devices if still in use, retire or replace affected routers rather than patching in place. If replacement must wait, block or firewall the web management interface from the internet, check the device for signs of compromise, and ensure the related authentication-bypass path CVE-2018-10561 is also closed.

9.8100% KEV ransomware PoC ×2
  • Dasan Gigabit Passive Optical Network (GPON) routers
mass≈1 million internet-exposed devices (public scan counts around the 2018 disclosure)
Full article540 words · extracted from securityaffairs.com · click to collapse

Experts at vpnMentor released an unofficial patch for Zero-Days in Dasan GPON home routers manufactured by the company Dasan.

Security experts at vpnMentor last week disclosed a couple of zero-day vulnerabilities (CVE-2018-10561 & CVE-2018-10562) in Gigabit-capable Passive Optical Network GPON home routers manufactured by the company Dasan.

The researchers have found a way to bypass the authentication to access the GPON home routers (CVE-2018-10561). The experts chained this authentication bypass flaw with another command injection vulnerability (CVE-2018-10562) and were able to execute commands on the device.

The GPON home routers are widely adopted by ISPs that offer fiber-optic Internet, it has been estimated that roughly one million of these devices are exposed to the Internet, most of them in Mexico, Kazakhstan, and Vietnam.

After the disclosure of the two vulnerabilities, experts started working on PoC exploit code, the Italian security expert Federico Valentini (@f3d_0x0), ICT Security researcher at  Cefriel, for example, published a Python exploit for Remote Code Execution on GPON home routers (CVE-2018-10562).

Security researchers at Qihoo 360 have monitored at least three campaigns targeting GPON home routers, one of them was involving the Mirai and Muhstik botnets.

one more thing, we captured a new mirai branch which also picked up this GPON vulnerability, so we are looking at at least three different campaigns going after the GPON now. (the .VN, the muhstik and mirai)

— 360 Netlab (@360Netlab) May 7, 2018

Waiting for the official patch from the manufacturer, vpnMentor researchers have released their unofficial patches for the two zero-days.

The deployment of the patch is quite simple, users simply have to enter the router’s local IP address and click the “Run Patch” button. The tool executes a script in the browser that allows users to disable the web server that represents the entry point for the attackers.

“All you have to do is input your infected router IP (it can be a local LAN address — it doesn’t have to be WAN) and a new password where you can access your router via LAN only SSH/Telnet, and our script will execute the patch.” states the post published by VPNmentor.

“Notice: By pressing “Patch”, you will execute the script yourself on the provided IP (whether local or WAN connected), since we use a client-side patch your browser will initiate.”

Once executed the patch, the router’s web interface will not be accessible from the browser (so it will not be exploited) and re-enabling the web server could not be so easy.

“This patch was not created by the official company and is not guaranteed. It was created to help mitigate the vulnerabilities until an official patch is released. Therefore, any issues or problems that might be caused by the use of this tool is not our responsibility, and we advise you to use it at your own risk.” reads the disclaimer for the patch.

“This tool disables the web server in a way that is not easy to reverse, it can be done with another patch script, but if you are not comfortable with the command line we suggest firewalling your device until an official patch is released.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – GPON home routers, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/72269/hacking/gpon-home-routers.html