Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
320x100 Itcentric
Banner Ancharia Desktop 1 1

CVE-2018-10562

View the latest critical CVEs issued
This is a free service offered by Red Hot Cyber to the community. It allows you to view, on a single page, information about a single CVE from the National Vulnerability Database (NVD) and the National Institute of Standards and Technology (NIST) of the United States of America, the Forum of Incident Response and Security Teams (FIRST) regarding the EPSS score and percentile, data from the KEV catalog of the Cybersecurity and Infrastructure Security Agency (CISA), as well as selected resources from Red Hot Cyber and other international sources.

National Vulnerability Database Information

Description: An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

CVSS Base Score: 9.8 (v3.1)

The **CVSS Base Score** is a score from **0 to 10** that represents the intrinsic severity of a vulnerability. A higher score indicates greater severity.

Value
0.02.55.07.510.0
Published on: 05/04/2018 03:29:00
Last modified: 11/05/2025 19:23:09
NIST: CVE source from the National Vulnerability Database (NVD)

CVSS Metrics Details

  • Base Severity: CRITICAL
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Privileges Required: NONE
  • User Interaction: NONE
  • Scope: UNCHANGED
  • Confidentiality Impact: HIGH
  • Integrity Impact: HIGH
  • Availability Impact: HIGH

Common Weakness Enumeration (CWE)

Database CWE: v4.18

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ↗

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Fonte: MITRE CWE


FIRST Information

EPSS Score: 0.9411

The **EPSS (Exploit Prediction Scoring System)** is a score from **0 to 1** that indicates the **probability** that a vulnerability will be exploited in the real world in the next 30 days. A higher value indicates a greater likelihood of exploitation.

Value
0.00.250.50.751.0

Percentile: 0.9990

The **Percentile** indicates how much higher this vulnerability's EPSS score is compared to all other vulnerabilities in the EPSS database. For example, a percentile of 0.90 (90%) means that 90% of vulnerabilities have an EPSS score equal to or lower than the current one.

Value
0.00.250.50.751.0

*Data updated as of: 2025-12-29


CISA Information (Known Exploited Vulnerabilities)

The **CISA KEV Catalog** lists vulnerabilities that have been **actively exploited in the real world**. If a CVE is present in this catalog, it indicates that the threat is immediate and mitigation should be a top priority.

CVE **CVE-2018-10562** **IS PRESENT** in the CISA KEV Catalog!

  • Vulnerability Name: Dasan GPON Routers Command Injection Vulnerability
  • Short Description: Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
  • Date Added to KEV: 03/31/2022
  • Vendor/Product: Dasan / Gigabit Passive Optical Network (GPON) Routers
  • Required Action: The impacted product is end-of-life and should be disconnected if still in use.
  • Due Date: 04/21/2022


Exploit PoC from GitHub

  • 649/Pingpon-Exploit: Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.
  • ATpiu/CVE-2018-10562: Exploit for CVE-2018-10562
  • ExiaHan/GPON: Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.
  • c0ld1/GPON_RCE: Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.
  • tpdlshdmlrkfmcla/backdoor.mirai.helloworld: backdoor.mirai.helloworld cve2018-20561, cve-2018-10562 해킹