CVE-2018-10562: Dasan GPON Devices - Remote Code Execution

HoneyLabs honeypots recorded 15 probes matching CVE-2018-10562 from 13 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /GponForm/diag_Form

Addresses probing it

Source IPProbesNetworkCountry
202.53.68.183Nettlinx LimitedIndia
103.26.81.791Cyber Internet Services (Pvt) Ltd.Pakistan
190.196.253.171MEGALINK S.R.L.Argentina
119.73.8.21IX Peering for Mobilink and Link Direct International.Pakistan
190.196.253.1161MEGALINK S.R.L.Argentina
115.56.150.2431CHINA UNICOM China169 BackboneChina
103.213.112.1411Cyber Internet Services (Pvt) Ltd.Pakistan
72.255.15.1061Cyber Internet Services (Pvt) Ltd.Pakistan

Networks it comes from

ASNOrganisationProbesSource IPs
AS9541Cyber Internet Services (Pvt) Ltd.44
AS10225Nettlinx Limited31
AS266702MEGALINK S.R.L.22
AS58470IX Peering for Mobilink and Link Direct International.11
AS197170TechTies Inc.11
AS142647Nasstec Airnet Networks Private Limited11

Captured requests

  • /GponForm/diag_Form?images/
  • /GponForm/diag_Form?style/

HTTP client fingerprints (JA4H)

  • po11nn0600_1386cd485c90
  • po11nn0500_ac885f862449
  • po11nn0600_f8bf768a441b

CVE report

CVE report

Open a specific CVE from the CVE tracker.