PT-2019-19969 · Dasan · Dasan H660Rm

Krzysztof Burghardt

·

Published

2019-04-11

·

Updated

2020-08-24

·

CVE-2019-9974

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions DASAN H660RM GPON routers with firmware 1.03-0022
Description The issue concerns a lack of authorization check in the diag tool.cgi component, allowing remote attackers to send a GET request and execute a ping command. This can be used to enumerate LAN devices or potentially crash the router with a Denial of Service (DoS) attack.
Recommendations For DASAN H660RM GPON routers with firmware 1.03-0022, consider restricting access to the diag tool.cgi component until a patch is available. As a temporary workaround, limiting the exposure of the router to the internet or implementing network segmentation to reduce the attack surface can help mitigate the risk.

Exploit

Fix

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9974

Affected Products

Dasan H660Rm