CyberSec.Space Logo
返回 CVE 浏览器

CVE-2018-10562

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score50.4150%
EPSS Percentile94.86th
Published2018年5月4日
Last Modified2025年11月5日

Vulnerability Description

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

Affected Platforms (CPE)

💻
Dasannetworks

Gpon Router Firmware

All versions

References & Advisories

相关漏洞威胁