Описание
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
Ссылки
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:dasannetworks:h660rm_firmware:1.03-0022:*:*:*:*:*:*:*
cpe:2.3:h:dasannetworks:h660rm:-:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06334
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 9.1
github
больше 3 лет назад
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
EPSS
Процентиль: 91%
0.06334
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-306