GPON home routers are affected by critical remote code vulnerabilities

Costea Lestoc By: Costea Lestoc
2 minute read
GPON home routers security issues

Home » News » GPON home routers are affected by critical remote code vulnerabilities

Security researchers recently tested a significant number of GPON home routers and unfortunately discovered a critical RCE vulnerability that could allow attackers to take full control over the affected devices. Researchers found that there’s a way to bypass the authentication in order to access the GPON home routers CVE-2018-10561. The flaw was linked by experts with another one CVE-2018-10562, and they were able to execute commands on the routers.

Hackers can take total control over routers

The two weaknesses mentioned above can be chained together in order to allow complete control over the vulnerable router and the network. The first vulnerability CVE-2018-10561 exploits the authentication mechanism of the device, and it can be exploited by attackers to bypass all authentication.

Since the router saves ping results in /tmp and transmits it to the user when the user revisits /diag.html, it’s quite simple to execute commands and retrieve their output with the authentication bypass vulnerability.

You can learn more about the way in which the exploit takes place by reading the security analysis to see all the tech details.


In case you want to be secure while surfing the internet, you will need to get a full-dedicated tool to secure your network.  Install now Cyberghost VPN and secure yourself. It protects your PC from attacks while browsing, masks your IP address and blocks all unwanted access.


Essential recommendations to avoid the exploit

Security researchers recommend the following steps to make sure that you remain safe:

  • Find out if your device is using the GPON network.
  • Remember that GPON devices can be hacked and exploited.
  • Discuss the matter with your ISP in order to see what they can do for you in order to fix the bug.
  • Warn your friends on social media about the serious threat.
  • Use the patch created to fix this problem.

RELATED STORIES TO CHECK OUT:

Discussions

Next up

5 easy-to-use movie maker software for Windows 10

Loredana Paraianu avatar. By: Loredana Paraianu
Less than a 1 minute read

Windows 10 users can find and use many video editors on the market. However, it is really difficult to select the most suitable video editing […]

Continue Reading

10 feature-rich PDF editors that are also very easy to use

Loredana Paraianu avatar. By: Loredana Paraianu
Less than a 1 minute read

The PDF format is one of the most popular file formats in the world. That’s why it is absolutely essential to have an excellent PDF […]

Continue Reading

3 best VPNs for Germany to bypass geo-restrictions in 2019

Loredana Paraianu avatar. By: Loredana Paraianu
7 minute read

Even if you live in one of the most developed countries in the world, where everything seems to work perfectly, computer privacy is often under […]

Continue Reading