PT-2019-19969 · Dasan · Dasan H660Rm
Krzysztof Burghardt
·
Published
2019-04-11
·
Updated
2020-08-24
·
CVE-2019-9974
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
DASAN H660RM GPON routers with firmware 1.03-0022
Description
The issue concerns a lack of authorization check in the
diag tool.cgi component, allowing remote attackers to send a GET request and execute a ping command. This can be used to enumerate LAN devices or potentially crash the router with a Denial of Service (DoS) attack.Recommendations
For DASAN H660RM GPON routers with firmware 1.03-0022, consider restricting access to the
diag tool.cgi component until a patch is available. As a temporary workaround, limiting the exposure of the router to the internet or implementing network segmentation to reduce the attack surface can help mitigate the risk.Exploit
Fix
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dasan H660Rm