Vulnerability record · CVE-2018-10562 · published 4 May 2018
CVE-2018-10562: Dasan GPON router command injection via dest_host parameter
Dasannetworks · Gpon Router Firmware
Dasan GPON home routers accept the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI without sanitizing it, allowing OS command injection. Because the router stores ping output in /tmp and serves it back at /diag.html, an attacker can run commands and read their results. The flaw is remotely reachable without credentials and carries a CVSS 3.1 base score of 9.8.
Description
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, no authentication or interaction required, KEV-listed with known ransomware use, and near-maximum EPSS probability.
What it is
Dasan GPON home routers accept the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI without sanitizing it, allowing OS command injection. Because the router stores ping output in /tmp and serves it back at /diag.html, an attacker can run commands and read their results. The flaw is remotely reachable without credentials and carries a CVSS 3.1 base score of 9.8.
Impact
An attacker gains arbitrary command execution on the router, which can lead to full device compromise, traffic interception, and use of the device as a foothold into the local network. CISA notes the product is end-of-life and that the vulnerability has been used in known ransomware campaigns.
Attack surface
Reached over the network via an HTTP request to the GponForm/diag_Form URI with a crafted dest_host value; the CVSS vector shows no privileges or user interaction required. Output retrieval requires revisiting /diag.html, but the injection itself needs no authentication.
Exploitation
Listed in CISA KEV since 2022-03-31 with known ransomware campaign use, and EPSS 30-day probability is 0.99949 (percentile 0.99973). Public exploit code exists (Exploit-DB 44576) and references are tagged Exploit.
What to do
- Apply the vendor patch if any is available; CISA states the product is end-of-life, so replace or disconnect affected Dasan GPON routers.
- Block or restrict external access to the GponForm/diag_Form and /diag.html endpoints at the network edge.
- Segment or isolate GPON routers from sensitive internal networks and management planes.
- Monitor for and remove any unauthorized configuration or persistence left by prior compromise.
- Inventory deployed Dasan GPON devices and prioritize remediation or decommissioning.
Detection
- Search web or proxy logs for requests to GponForm/diag_Form with diag_action=ping and suspicious dest_host values containing shell metacharacters.
- Alert on access to /diag.html following such requests, which may indicate output retrieval.
- Monitor router or upstream traffic for outbound connections to unknown hosts consistent with command-and-control.
- Review device logs for unexpected command execution or file writes under /tmp.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-10562 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Dasan GPON Routers Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 21 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/107053 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44576/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ | ExploitTechnical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/107053 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/44576/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ | ExploitTechnical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-10562 | US Government Resource |
Track CVE-2018-10562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10562), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.