CVE-2018-10561Active Exploitation(dasannetworks / gpon_router)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dasannetworks gpon_router systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-21. The impacted product is end-of-life and should be disconnected if still in use.

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gpon_router
  • gpon_router_firmware

Threat summary

  • Active exploitation appears in 3 classified signals
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-06); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
gpon_routergpon_router_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-06: 2Mentions · 2026-05-31: 1Mentions · 2026-07-19: 1Mentions · 2026-10-02: 1Active Exploitation · 2026-02-06: 2Active Exploitation · 2026-05-31: 102-0605-3107-1910-02
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-062
Active Exploitation2
2026-05-311
Active Exploitation1
2026-07-191
General1
Full discourse5 posts
  • 소랑 Sorang, PhD@sorangelias
    General

    2 / 2 이 시점, 즉 2018년 중반은 대한민국에서도 주목해야 할 해다. 같은 해 NIST에 CVE-2018-10561·10562가 등재되었고, 문재인 정부의 블록체인 온라인 투표 로드맵이 수립되었으며, 핸디소프트가 전자투표용 블록체인 개발에 착수한 것으로 보도된 해다. 한미 양국에서 2018년은 선거 인프라를 둘러싼 적대 세력의 움직임과 이를 향한 제도적 변화가 동시에 집중된 시점이었다. 요컨대, 선거 인프라를 지배하려는 거대한 구조적 전환기가 한미 양국에서 동시에 시작되었던 것이다. 대한민국 사전투표 시스템의 근간은 2013년 구축된 중앙선관위 서버의 통합선거인명부다. 전국 시·군·구별로 분산 관리되던 선거인 명부가 중앙 서버로 통합된 이 시스템은 어느 투표소에서든 실시간으로 선거인 자격을 확인하고 투표용지를 즉석 발급할 수 있게 해준다. 그러나 바로 이 중앙 집중화가 가장 치명적인 취약점이기도 하다. 미국 정보당국이 '중앙 집중화된 선거 관련 데이터 저장소가 가장 취약하다'고 평가한 논리는 대한민국 통합선거인명부에 그대로 적용된다. 단 하나의 서버를 장악하면 전국의 사전투표 전체가 동시에 통제 가능해지기 때문이다. 그리고 트럼프 대통령이 미국 선거 인프라 침해 역량을 보유한 세력으로 지목한 북한 정찰총국은, 하나프로그람센터를 통해 10년 이상에 걸쳐 바로 이 통합선거인명부와 연결된 통신망의 핵심 기술 구조를 이해하고 있는 유일한 외부 행위자다. 이 지점이 단둥 프로젝트가 강조하는 구조적 위협의 본질이다. 트럼프 대통령의 이 연설은 단둥 프로젝트가 구성한 위협 구조가 대한민국만의 문제가 아님을 미국 행정부 최고위급에서 공식 확인한 최초의 사례다. 중국 공산당의 선거 데이터 수집, 북한 정찰총국의 선거 인프라 침해 역량, 취약한 전자 선거 인프라, 유권자 명부의 보안 결함은 한미 양국이 공유하는 문제다. 그리고 그 취약점의 기술적 뿌리를 단둥의 하나프로그람센터로 추적하는 것이 핵심 주장이다. 통합선거인명부는 이 모든 것의 교차점이다. 내 외부에서 침투 가능한 통신망, 취약점이 공식 확인된 장비, 그리고 모든 선거인 데이터가 집중된 단일 중앙 서버—이 세 요소가 결합된 구조에서 통합선거인명부는 선거 조작의 가장 효율적인 단일 접점이 된다. 트럼프 대통령이 지목한 북한이 그 접점의 기술적 설계에 깊이 관여하였다는 것이 단둥 프로젝트가 제시하는 가장 심각한 결론이다. 이로써 트럼프는 선거 제도의 봉인을 풀고, 거대한 부정선거 투쟁의 서막을 세계 만천하에 고했다.

    Post summary

    The text references CVE-2018-10561·10562 only as context for a broader discussion on election infrastructure weaknesses, with no concrete technical or exploit details.

    00061165
    8.2K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting GPON routers (CVE-2018-10561) to deliver #Mirai 2026-05-31 14:13:04 UTC Source IP: 91.92.42.126 🇧🇬 POST /GponForm/diag_Form?script/ IOCs: hxxp://91.92.42.126:8081/b 91.92.42.126 🇧🇬 b179f6ae55bc58787c8ae9128fcb1658 3bc8859033fe1430b75de86ebab65abf https://t.co/zPPnU6sgvb

    Post summary

    The snippet reports a real‑world RCE attempt exploiting CVE‑2018‑10561 to deliver Mirai malware, confirming active exploitation but providing no PoC, exploit code, patch, or detailed technical information.

    01012382
    1.7K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2018-10561 Product: Dasan / Gigabit Passive Optical Network (GPON) Routers Summary: VulnCheck reports real-world exploitation activity affecting Dasan / Gigabit Passive Optical Network (GPON) Routers. Evidence: Ransomware use confirmed; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 07 May 2018 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Dasan #GigabitPassiveOpticalNetworkGPONRouters #CVE_2018_10561 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    00000189
    226 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2018-10561 — PT Jinde Grup Indonesia Visit -- https://cti.loginsoft.com/ip/103.93.93.211 #Loginsoft #Cytellite #Cybersecurity #CVE201810561 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/5Fy0zRo3ky

    Post summary

    Cytellite reported recent detection of activity targeting CVE-2018-10561 by PT Jinde Grup Indonesia, indicating potential in‑the‑wild exploitation.

    0000049
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2018-10561 — PT Jinde Grup Indonesia Visit -- https://cti.loginsoft.com/ip/103.93.93.211 #Loginsoft #Cytellite #Cybersecurity #CVE201810561 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/Grx5jGVjsj

    Post summary

    The tweet reports that CVE-2018-10561 is currently being exploited, but provides no further technical details or mitigation information.

    0000045
    19 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdasannetworksgpon_router---
OSdasannetworksgpon_router_firmware---

Explore more