An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/107053 | broken link vdb entry third party advisory |
https://www.exploit-db.com/exploits/44576/ | exploit vdb entry third party advisory |
https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/ | technical description exploit third party advisory |