An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-05-04T03:00:00

Updated: 2024-08-05T07:39:08.323Z

Reserved: 2018-04-30T00:00:00

Link: CVE-2018-10561

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-05-04T03:29:00.227

Modified: 2019-03-04T18:39:11.630

Link: CVE-2018-10561

cve-icon Redhat

No data.