Dasan Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Dasan products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

2

Beyond CISA KEV

1

Sensor Observed

1

Virtual Patch Available

1

Dasan KEVs Added by Year

Loading...

3 Dasan KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-10561

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device...

Confirmed In CISA 31 Mar 2022
CVE-2018-10562

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a...

Confirmed In CISA 31 Mar 2022
CVE-2017-18046

Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary...

High Not in CISA 21 Jan 2018

Common Vulnerability Classes (CWE)

  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
  • CWE-287 — Improper Authentication 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology