Loading
Generated remediation guidance and an executive summary. No account required.
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
Use CWE-287, Dasannetworks vendor hub and Gpon Router Firmware product page to widen CVE-2018-10561 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-10562 for nearby disclosures in the same product family.