Skip to content
COOEY

FAIL › dossier

Dasan

VENDOR

· dossier confidence 80%

Dasan is a telecommunications hardware vendor whose GPON routers have suffered critical and high-severity remote code execution vulnerabilities due to authentication bypass flaws. These vulnerabilities were actively exploited in the wild, indicating a significant failure in the vendor's security development lifecycle and patch management processes.

PROFILE
Categorytelecommunications hardware vendorWhat they doDasan manufactures GPON routers and other telecommunications equipment.
SECURITY POSTURE

Dasan has a poor security posture, evidenced by critical and high-severity remote code execution vulnerabilities in its GPON routers that were actively exploited in the wild.

Notable failures
  • CVE-2018-10561: Authentication bypass leading to RCE in GPON routers
  • CVE-2018-10562: Critical authentication bypass allowing RCE in GPON routers
Patterns: authentication bypass vulnerabilities in edge devices; unpatched RCE flaws in telecommunications hardware
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-31 CVE-2018-10561 high Dasan GPON routers have an authentication bypass flaw that, when combined with another vulnerability, allows remote code execution.
2022-03-31 CVE-2018-10562 critical Dasan GPON routers have a critical authentication bypass vulnerability allowing remote code execution when combined with another flaw, and are currently being exploited in the wild.
Open questions: Dasan's current patch management practices for existing GPON router firmware · Whether Dasan has issued any security advisories or patches for CVE-2018-10561 and CVE-2018-10562
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:47:17.366160+00:00