S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-10562 Scanner

CVE-2018-10562 scanner - Command Injection vulnerability in GPON Home Routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-10562
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

GPON Home Routers are used as a home networking device that enables internet access across various devices. These routers use Gigabit Passive Optical Network (GPON) technology to provide users with a high-speed internet connection. The GPON Home Routers software is designed to make the digital experience at home more seamless and efficient. It provides features such as Wi-Fi connectivity, port forwarding, firewall protections, and parental controls. With the increased dependency on the internet, GPON Home Routers have become an essential aspect of modern-day living.

CVE-2018-10562 is a vulnerability discovered in the Dasan GPON Home Routers. The issue is caused by command injection, which can occur when a ping request is made with a specific parameter to the GponForm/diag_Form URI. The dest_host parameter can be exploited to execute arbitrary commands on the router, leading to unauthorized access to the device. The vulnerability allows an attacker to gain access to crucial information, including usernames and passwords, network configurations, and other sensitive data.

Exploiting the vulnerability above can have devastating consequences. Once an attacker gains access to the GPON Home Router, they can launch other more advanced attacks on other connected devices. An attacker can use this vulnerability to install malware or spyware, steal personal data, make unauthorized transactions, and launch DDoS attacks. This vulnerability poses a security threat to both individuals and businesses, making it essential to keep devices updated with the latest security patches and protocols.

At s4e.io, we understand the importance of protecting your digital assets from cyber threats. Our platform offers features that enable individuals, businesses, and organizations to identify and mitigate vulnerabilities in their digital infrastructure. With our pro features, you can easily and quickly learn about vulnerabilities, assess their impact and take appropriate actions. We believe that everyone deserves to be safe in an increasingly interconnected world, and we are committed to delivering on our promise of S4E.

 

REFERENCES

Solution Advice

To protect against this vulnerability, GPON Home Router users can take a few precautionary measures:

  • Update the firmware regularly, ensuring that the router has the latest security patches.
  • Disable the remote management feature in the router.
  • Change the default password to a strong one.
  • Use a strong Wi-Fi network password.
  • Disable unused services and ports on the router.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.