LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-10561: Dasan GPON Routers Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 31, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-10561 to its Known Exploited Vulnerabilities catalog on Mar 31, 2022, with a federal patch deadline of Apr 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

CVE-2018-10561 is an authentication bypass vulnerability in Dasan Gigabit Passive Optical Network (GPON) routers. It allows an attacker to circumvent normal login controls on the device. When combined with CVE-2018-10562, exploitation can enable remote code execution. These routers often sit at the edge of home or small-business networks, so a successful bypass can give an attacker a foothold on the local network and any devices behind it. The product is end-of-life; CISA advises disconnecting any remaining units.

How it works

The flaw belongs to CWE-287, improper authentication. In this class of weakness the device fails to correctly enforce identity checks before granting access to protected functions or interfaces. An attacker who can reach the router’s management surface can abuse the bypass to obtain privileges that should require valid credentials. Public detail on the exact request sequence or parameters is limited; defenders should treat any unauthenticated access to administrative or diagnostic endpoints as a potential abuse path and confirm specifics against the original vendor advisory. Once authentication is bypassed, the companion issue CVE-2018-10562 can be leveraged to achieve remote code execution, giving the attacker the ability to run arbitrary commands on the device.

Am I affected? How to find it in your systems

Dasan GPON routers are typically deployed by internet service providers as customer-premises equipment that terminates fiber connections. They appear in residential gateways, multi-dwelling units, and some small-office environments. Inventory steps include:

Telemetry signs of exploitation may include unexpected administrative sessions, configuration changes, or command execution from untrusted source addresses. Because the product is end-of-life, any still-active unit should be treated as high risk regardless of observed traffic.

How to remediate

The definitive remediation is to remove the device from service. CISA’s required action states that the impacted product is end-of-life and should be disconnected if still in use. Replace it with a supported router or ONT supplied or approved by the service provider. If a vendor patch or firmware update was ever published for this CVE, apply it only after confirming the exact fixed version in the original advisory; do not assume any particular release number. After replacement, re-image or factory-reset any downstream equipment that may have been exposed, change all credentials that traversed the old device, and verify that management interfaces on the new gear are not reachable from untrusted networks.

If you can't patch immediately

Immediate disconnection is the preferred control. Where operational constraints force temporary continued use, apply these compensating measures:

These steps only reduce exposure; they do not eliminate the underlying authentication bypass. Plan replacement without delay.

If your data may have been exposed

Actively exploited authentication-bypass and remote-code-execution chains on edge routers frequently lead to network compromise and data theft. If the device was internet-facing or showed signs of unauthorized access, assume credentials, session tokens, or traffic that traversed it may have been observed. Rotate passwords, review firewall and endpoint logs for lateral movement, and consider a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDasan · Gigabit Passive Optical Network (GPON) Routers
WeaknessCWE-287
Added to CISA KEVMar 31, 2022
Federal patch deadlineApr 21, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities