EXPOSURES › CVE-2018-10561
CVE-2018-10561
HIGH ⌖ ON CISA KEV · EXPLOITEDDasan GPON routers have an authentication bypass flaw that, when combined with another vulnerability, allows remote code execution.
The authentication bypass in Dasan GPON routers, when chained with CVE-2018-10562, enables remote code execution, posing a severe risk to network infrastructure. DIB organizations must ensure these devices are patched or replaced, as unpatched instances could be exploited in the wild to compromise network integrity. This failure highlights the danger of relying on unpatched hardware in critical communications networks.
Shame score — The vulnerability allows remote code execution when chained with another flaw, and the hardware is actively exploited in the wild, indicating a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.