CVE-2018-10562 is a critical command injection vulnerability affecting Dasan GPON home routers, specifically via the dest_host parameter in a diag_action=ping request to the GponForm/diag_Form URI. This flaw allows unauthenticated remote attackers to execute arbitrary commands due to improper input validation and the router's method of saving and transmitting ping results. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit code and Nuclei templates, indicating widespread community and attacker interest. Media coverage also confirms its use in botnet campaigns.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dasannetworks:gpon_router_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.