← Back to browse · API

CVE-2018-10561

Severity
CRITICAL
CVSS
9.8
EPSS
0.92371
Risk score
57.33
CISA KEV
Yes
PoC
No
Published
2018-05-04
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-2633, GHSA-9F5C-V3C9-RFHG
Products
Dasan:Gigabit Passive Optical Network (GPON) Routers, n/a:n/a n/a
Sources
cisa.gov CVE-2018-10561
euvd EUVD-2018-2633

Description

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

References