CVE-2018-10561 is a critical authentication bypass vulnerability affecting Dasan GPON home routers, allowing unauthenticated attackers to gain full device management access by simply appending "?images" to any authenticated URL. With a CVSS score of 9.8 and an EPSS score indicating high exploitability, this flaw presents a severe risk. It is actively exploited in the wild, with public exploit code available on ExploitDB and significant community discussion and media coverage highlighting its widespread impact, including botnet activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dasannetworks:gpon_router_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.