CISA Known Exploited Vulnerability

CVE-2018-10562 Ransomware

Dasan · Gigabit Passive Optical Network (GPON) Routers

Dasan GPON Routers Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Known

CISA description

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

Required action

The impacted product is end-of-life and should be disconnected if still in use.