← Vulnerability feed

Vulnerability record · CVE-2018-10561 · published 4 May 2018

CVE-2018-10561: Dasan GPON routers authentication bypass via URL suffix

Dasannetworks · Gpon Router Firmware

Dasan GPON home routers can be accessed without authentication by appending "?images" to any protected URL, such as /menu.html?images/ or /GponForm/diag_FORM?images. This lets an unauthenticated remote attacker reach administrative functionality and manage the device. The flaw is rated critical and the affected product is end-of-life.

9.8 CVSS 3.1 Critical CISA KEV since 31 Mar 2022 EPSS 93% · top 0.2% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing, very high EPSS probability, public exploits, and no patch for an end-of-life device make this an urgent exposure.

What it is

Dasan GPON home routers can be accessed without authentication by appending "?images" to any protected URL, such as /menu.html?images/ or /GponForm/diag_FORM?images. This lets an unauthenticated remote attacker reach administrative functionality and manage the device. The flaw is rated critical and the affected product is end-of-life.

Impact

An attacker gains full administrative control of the router, including the ability to change configuration and manage the device. Because the device sits at the network edge, this can expose or redirect the connected network.

Attack surface

Reachable over the network via HTTP requests to the router's web interface; no authentication is required and no user interaction is needed. The CVSS vector confirms network access with no privileges or UI.

Exploitation

The vulnerability is listed in CISA KEV, has an EPSS 30-day probability of 0.92893 (99.8th percentile), and public exploit references exist on Exploit-DB and a technical writeup. No ransomware campaign use is documented.

What to do

  • Disconnect or replace end-of-life Dasan GPON routers, as CISA directs; no vendor patch is available for this product.
  • If the device must remain temporarily, block its web management interface from untrusted networks and restrict access to a trusted management segment.
  • Place the router behind a firewall or access control list that denies inbound HTTP to the management interface.
  • Monitor for and remove any unauthorized configuration changes if the device has been exposed.
  • Inventory all Dasan GPON devices on the network and track them for decommissioning.

Detection

  • Inspect HTTP request logs for URLs containing "?images" appended to protected paths such as /menu.html or /GponForm/diag_FORM.
  • Alert on unauthenticated access to administrative endpoints on GPON router management interfaces.
  • Monitor for unexpected configuration changes or new administrative sessions on these routers.
  • Watch for outbound connections from the router to unknown hosts that could indicate compromise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-10561 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Dasan GPON Routers Authentication Bypass Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 21 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/107053 Broken LinkThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44576/ ExploitThird Party AdvisoryVDB Entry
https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ ExploitTechnical DescriptionThird Party Advisory
http://www.securityfocus.com/bid/107053 Broken LinkThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44576/ ExploitThird Party AdvisoryVDB Entry
https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ ExploitTechnical DescriptionThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-10561 US Government Resource

Track CVE-2018-10561 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-10562Dasan GPON router command injection via dest_host parameterDasan GPON home routers accept the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI without sanitizing it, allowing OS…KEVEPSS 100%analysed7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.3CVE-2026-16232Check Point SmartConsole authentication bypass grants admin tokenCheck Point SmartConsole login contains an improper authentication flaw (CWE-287) that lets an unauthenticated remote attacker obtain an application …KEVEPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2018-10561), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.