EXPOSURES › CVE-2018-10562
CVE-2018-10562
CRITICAL ⌖ ON CISA KEV · EXPLOITEDDasan GPON routers have a critical authentication bypass vulnerability allowing remote code execution when combined with another flaw, and are currently being exploited in the wild.
Dasan GPON routers are vulnerable to command injection, enabling attackers to bypass authentication and execute code remotely when paired with CVE-2018-10561. DIB organizations using these routers face significant exposure and potential compliance failures under CMMC/NIST 800-171; immediate patching and network segmentation are required.
Shame score — The combination of an authentication bypass and remote code execution, coupled with active exploitation, demonstrates a significant security oversight and potential for widespread compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.