CVE-2017-18046 describes a critical buffer overflow vulnerability in Dasan GPON ONT WiFi Router H640X devices, specifically firmware versions 12.02-01121 2.77p1-1124 and 3.03p2-1146. This flaw allows unauthenticated remote attackers to execute arbitrary code by sending an excessively long POST request to the login_action function. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild, nor publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media attention, indicating a high level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.77p1-1124CPE matchmatch criteria | cpe:2.3:o:dasannetworks:h640x_firmware:2.77p1-1124:*:*:*:*:*:*:* | ||
3.03p2-1146CPE matchmatch criteria | cpe:2.3:o:dasannetworks:h640x_firmware:3.03p2-1146:*:*:*:*:*:*:* | ||
12.02-01121CPE matchmatch criteria | cpe:2.3:o:dasannetworks:h640x_firmware:12.02-01121:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.