FAIL › dossier
Dasan
VENDOR· dossier confidence 80%
Dasan is a telecommunications hardware vendor whose GPON routers have suffered critical and high-severity remote code execution vulnerabilities due to authentication bypass flaws. These vulnerabilities were actively exploited in the wild, indicating a significant failure in the vendor's security development lifecycle and patch management processes.
PROFILE
Categorytelecommunications hardware vendorWhat they doDasan manufactures GPON routers and other telecommunications equipment.
SECURITY POSTURE
Dasan has a poor security posture, evidenced by critical and high-severity remote code execution vulnerabilities in its GPON routers that were actively exploited in the wild.
Notable failures
- CVE-2018-10561: Authentication bypass leading to RCE in GPON routers
- CVE-2018-10562: Critical authentication bypass allowing RCE in GPON routers
Patterns: authentication bypass vulnerabilities in edge devices; unpatched RCE flaws in telecommunications hardware
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-31 | CVE-2018-10561 | high | Dasan GPON routers have an authentication bypass flaw that, when combined with another vulnerability, allows remote code execution. |
| 2022-03-31 | CVE-2018-10562 | critical | Dasan GPON routers have a critical authentication bypass vulnerability allowing remote code execution when combined with another flaw, and are currently being exploited in the wild. |
Open questions: Dasan's current patch management practices for existing GPON router firmware · Whether Dasan has issued any security advisories or patches for CVE-2018-10561 and CVE-2018-10562
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:47:17.366160+00:00