An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-05-04T03:00:00
Updated: 2024-08-05T07:39:08.323Z
Reserved: 2018-04-30T00:00:00
Link: CVE-2018-10561
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-05-04T03:29:00.227
Modified: 2024-11-21T03:41:33.423
Link: CVE-2018-10561
Redhat
No data.