Lucene search

K

Dasannetworks Security Vulnerabilities

cve
cve

CVE-2023-42495

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...

9.8CVSS

9.4AI Score

0.001EPSS

2023-12-13 01:15 PM
11
cve
cve

CVE-2019-8950

The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via...

9.8CVSS

9.3AI Score

0.003EPSS

2022-10-03 04:19 PM
25
cve
cve

CVE-2019-9974

diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS...

9.1CVSS

9.2AI Score

0.007EPSS

2019-04-11 07:29 PM
45
cve
cve

CVE-2019-9975

DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this...

7.5CVSS

7.4AI Score

0.005EPSS

2019-04-11 07:29 PM
49
cve
cve

CVE-2019-9976

The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface...

8.8CVSS

8.5AI Score

0.001EPSS

2019-04-11 07:29 PM
49
cve
cve

CVE-2018-17867

The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address...

7.2CVSS

7.5AI Score

0.005EPSS

2018-10-01 11:29 PM
20
cve
cve

CVE-2018-10561

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the...

9.8CVSS

9.4AI Score

0.971EPSS

2018-05-04 03:29 AM
1091
In Wild
12
cve
cve

CVE-2018-10562

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple...

9.8CVSS

9.8AI Score

0.974EPSS

2018-05-04 03:29 AM
1096
In Wild
3
cve
cve

CVE-2017-18046

Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka...

9.8CVSS

9.8AI Score

0.047EPSS

2018-01-21 10:29 PM
20