Vulnerability record · CVE-2018-10561 · published 4 May 2018
CVE-2018-10561: Dasan GPON routers authentication bypass via URL suffix
Dasannetworks · Gpon Router Firmware
Dasan GPON home routers can be accessed without authentication by appending "?images" to any protected URL, such as /menu.html?images/ or /GponForm/diag_FORM?images. This lets an unauthenticated remote attacker reach administrative functionality and manage the device. The flaw is rated critical and the affected product is end-of-life.
Description
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, very high EPSS probability, public exploits, and no patch for an end-of-life device make this an urgent exposure.
What it is
Dasan GPON home routers can be accessed without authentication by appending "?images" to any protected URL, such as /menu.html?images/ or /GponForm/diag_FORM?images. This lets an unauthenticated remote attacker reach administrative functionality and manage the device. The flaw is rated critical and the affected product is end-of-life.
Impact
An attacker gains full administrative control of the router, including the ability to change configuration and manage the device. Because the device sits at the network edge, this can expose or redirect the connected network.
Attack surface
Reachable over the network via HTTP requests to the router's web interface; no authentication is required and no user interaction is needed. The CVSS vector confirms network access with no privileges or UI.
Exploitation
The vulnerability is listed in CISA KEV, has an EPSS 30-day probability of 0.92893 (99.8th percentile), and public exploit references exist on Exploit-DB and a technical writeup. No ransomware campaign use is documented.
What to do
- Disconnect or replace end-of-life Dasan GPON routers, as CISA directs; no vendor patch is available for this product.
- If the device must remain temporarily, block its web management interface from untrusted networks and restrict access to a trusted management segment.
- Place the router behind a firewall or access control list that denies inbound HTTP to the management interface.
- Monitor for and remove any unauthorized configuration changes if the device has been exposed.
- Inventory all Dasan GPON devices on the network and track them for decommissioning.
Detection
- Inspect HTTP request logs for URLs containing "?images" appended to protected paths such as /menu.html or /GponForm/diag_FORM.
- Alert on unauthenticated access to administrative endpoints on GPON router management interfaces.
- Monitor for unexpected configuration changes or new administrative sessions on these routers.
- Watch for outbound connections from the router to unknown hosts that could indicate compromise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-10561 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Dasan GPON Routers Authentication Bypass Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 21 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/107053 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44576/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ | ExploitTechnical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/107053 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44576/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ | ExploitTechnical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-10561 | US Government Resource |
Track CVE-2018-10561 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10561), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.