Dasannetworks develops a focused portfolio of GPON routers and broadband access equipment deployed in telecommunications and residential networks, with vulnerabilities skewing strongly toward critical-severity outcomes. The exposure recurs across products such as the H660RM and DS2924 through structural weaknesses including OS command injection, missing authentication for critical functions, hard-coded credentials, and memory-safety issues endemic to embedded networking firmware, and these vulnerabilities have an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability. Defenders should prioritize inventory and patching of exposed Dasannetworks equipment, particularly internet-facing or remotely managed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dasannetworks over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10562CRITICAL An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the r | May 4, 2018 | 9.8 | 98 | YES | YES |
CVE-2018-10561CRITICAL An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as | May 4, 2018 | 9.8 | 97 | YES | YES |
CVE-2025-63206CRITICAL An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via | Nov 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2017-18046CRITICAL Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the | Jan 21, 2018 | 9.8 | 34 | NO | NO |
CVE-2019-8950CRITICAL The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET. | Feb 20, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-42495CRITICAL
Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Dec 13, 2023 | 9.8 | 24 | NO | NO |
CVE-2018-17867HIGH The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr paramete | Oct 1, 2018 | 7.2 | 24 | NO | NO |
CVE-2019-9974CRITICAL diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate | Apr 11, 2019 | 9.1 | 23 | NO | NO |
CVE-2019-9976HIGH The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of admin | Apr 11, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9975HIGH DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key. | Apr 11, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dasannetworks.
Media articles that mention a CVE ID that affects a product developed by Dasannetworks — matched by CVE ID, not by vendor name.