Dasan Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Dasan products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
2
Beyond CISA KEV
1
Sensor Observed
1
Virtual Patch Available
1
Dasan KEVs Added by Year
3 Dasan KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-10561
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device... |
GPON home routers | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2018-10562
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a... |
GPON home routers | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2017-18046
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary... |
GPON ONT WiFi Router H640X | High | Not in CISA | 21 Jan 2018 |
Common Vulnerability Classes (CWE)
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
- CWE-287 — Improper Authentication 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology