CVE Intel / CVE-2018-10562
CVE-2018-10562
gpon router · dasannetworks
What it is
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
Live exploitation on the huntback network (30 days)
2
attempts captured
2
distinct source IPs
2026-09-23
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.
How huntback helps
Deploy a decoy that emulates gpon router and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.
CVSSn/a Critical
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured