Hacking

Experts released an unofficial patch for Zero-Days in Dasan GPON home routers

Experts at vpnMentor released an unofficial patch for Zero-Days in Dasan GPON home routers manufactured by the company Dasan.

Security experts at vpnMentor last week disclosed a couple of zero-day vulnerabilities (CVE-2018-10561 & CVE-2018-10562) in Gigabit-capable Passive Optical Network GPON home routers manufactured by the company Dasan.

The researchers have found a way to bypass the authentication to access the GPON home routers (CVE-2018-10561). The experts chained this authentication bypass flaw with another command injection vulnerability (CVE-2018-10562) and were able to execute commands on the device.

GPON Home Routers hackGPON Home Routers hack

The GPON home routers are widely adopted by ISPs that offer fiber-optic Internet, it has been estimated that roughly one million of these devices are exposed to the Internet, most of them in Mexico, Kazakhstan, and Vietnam.

After the disclosure of the two vulnerabilities, experts started working on PoC exploit code, the Italian security expert Federico Valentini (), ICT Security researcher at  Cefriel, for example, published a Python exploit for Remote Code Execution on GPON home routers (CVE-2018-10562).

Security researchers at Qihoo 360 have monitored at least three campaigns targeting GPON home routers, one of them was involving the Mirai and Muhstik botnets.

Waiting for the official patch from the manufacturer, vpnMentor researchers have released their unofficial patches for the two zero-days.

The deployment of the patch is quite simple, users simply have to enter the router’s local IP address and click the “Run Patch” button. The tool executes a script in the browser that allows users to disable the web server that represents the entry point for the attackers.

“All you have to do is input your infected router IP (it can be a local LAN address — it doesn’t have to be WAN) and a new password where you can access your router via LAN only SSH/Telnet, and our script will execute the patch.” states the post published by VPNmentor.

“Notice: By pressing “Patch”, you will execute the script yourself on the provided IP (whether local or WAN connected), since we use a client-side patch your browser will initiate.”

Once executed the patch, the router’s web interface will not be accessible from the browser (so it will not be exploited) and re-enabling the web server could not be so easy.

“This patch was not created by the official company and is not guaranteed. It was created to help mitigate the vulnerabilities until an official patch is released. Therefore, any issues or problems that might be caused by the use of this tool is not our responsibility, and we advise you to use it at your own risk.” reads the disclaimer for the patch.

“This tool disables the web server in a way that is not easy to reverse, it can be done with another patch script, but if you are not comfortable with the command line we suggest firewalling your device until an official patch is released.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – GPON home routers, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Czech Republic accuses China’s APT31 of a cyberattack on its Foreign Ministry

The Czech government condemned China after linking cyber espionage group APT31 to a cyberattack on…

4 hours ago

New PumaBot targets Linux IoT surveillance devices

PumaBot targets Linux IoT devices, using SSH brute-force attacks to steal credentials, spread malware, and…

8 hours ago

App Store Security: Apple stops $2B in fraud in 2024 alone, $9B over 5 years

Apple blocked over $9B in fraud in 5 years, including $2B in 2024, stopping scams…

9 hours ago

Crooks use a fake antivirus site to spread Venom RAT and a mix of malware

Researchers found a fake Bitdefender site spreading the Venom RAT by tricking users into downloading…

13 hours ago

Iranian Man pleaded guilty to role in Robbinhood Ransomware attacks<gwmw style="display:none;"></gwmw>

Iranian man pleads guilty to role in Baltimore ransomware attack tied to Robbinhood, admitting to…

14 hours ago

DragonForce operator chained SimpleHelp flaws to target an MSP and its customers

Sophos warns that a DragonForce ransomware operator chained three vulnerabilities in SimpleHelp to target a…

1 day ago