dasannetworks CVE Vulnerabilities & CVE List (10)

Products (CPE): — CVEs: 10

dasannetworks vulnerability overview

Aggregates CVE and security vulnerability intelligence across all dasannetworks-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk buffer overflow, vendor risk denial of service, and vendor risk command injection and related problems; some flaws may lead to vendor impact application crash.

Vulnerability distribution trend (last 24 months)

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-63206 An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser. [email protected] 9.8 0.14% 2025-11-19 2025-12-31
CVE-2023-42495 Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') [email protected] 9.8 0.35% 2023-12-13 2024-11-21
CVE-2019-9976 The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users. [email protected] 8.8 0.31% 2019-04-11 2024-11-21
CVE-2019-9975 DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key. [email protected] 7.5 0.34% 2019-04-11 2024-11-21
CVE-2019-9974 diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack. [email protected] 9.1 1.64% 2019-04-11 2024-11-21
CVE-2019-8950 The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET. [email protected] 9.8 0.89% 2019-02-20 2024-11-21
CVE-2018-17867 The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field). [email protected] 7.2 4.42% 2018-10-01 2024-11-21
CVE-2018-10562 KEV An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output. [email protected] 9.8 94.03% 2018-05-04 2025-11-05
CVE-2018-10561 KEV An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device. [email protected] 9.8 93.31% 2018-05-04 2025-11-05
CVE-2017-18046 Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi). [email protected] 9.8 5.48% 2018-01-21 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence