Skip to content
COOEY

FAIL › dossier

Gigabit Passive Optical Network (GPON) Routers

PRODUCT

· dossier confidence 20%

Dasan Networks' GPON routers are plagued by critical, actively exploited authentication bypass vulnerabilities that enable remote code execution, representing a severe risk to telecommunications infrastructure and requiring immediate decommissioning or patching.

PROFILE
CategorytelecommunicationsWhat they doDasan Networks manufactures Gigabit Passive Optical Network (GPON) routers and optical network terminals for telecommunications service providers. Websitehttps://www.dasan.com ↗
SECURITY POSTURE

Dasan Networks has a poor security posture, evidenced by critical and high-severity remote code execution vulnerabilities in its GPON routers that were actively exploited and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Notable failures
  • CVE-2018-10561: Critical authentication bypass leading to RCE in GPON routers
  • CVE-2018-10562: Critical authentication bypass leading to RCE in GPON routers
  • Active exploitation of GPON router vulnerabilities by threat actors
Patterns: repeated unpatched authentication bypasses in edge-network devices; critical RCE vulnerabilities in long-deployed optical network equipment
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-31 CVE-2018-10561 high Dasan GPON routers have an authentication bypass flaw that, when combined with another vulnerability, allows remote code execution.
2022-03-31 CVE-2018-10562 critical Dasan GPON routers have a critical authentication bypass vulnerability allowing remote code execution when combined with another flaw, and are currently being exploited in the wild.
Open questions: What is the current patch status for CVE-2018-10561 and CVE-2018-10562? · Are there other unpatched vulnerabilities in Dasan GPON routers?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:51:09.578354+00:00