CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “dasannetworks”

10 vulnerabilities found for “dasannetworks”

CVE-2025-63206
CRITICAL9.8

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.

dasannetworks / ds2924_firmware+1
Network
Published Nov 19, 2025
CVE-2023-42495
CRITICAL9.8

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

dasannetworks / w-web
Network
Published Dec 13, 2023
CVE-2019-9974
CRITICAL9.1

diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.

dasannetworks / h660rm_firmware
Network
Published Apr 11, 2019
CVE-2019-9976
HIGH8.8

The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.

dasannetworks / h660rm_firmware
Network
Published Apr 11, 2019
CVE-2019-9975
HIGH7.5

DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.

dasannetworks / h660rm_firmware
Network
Published Apr 11, 2019
CVE-2019-8950
CRITICAL9.8

The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.

dasannetworks / h665_firmware
Network
Published Feb 20, 2019
CVE-2018-17867
HIGH7.2

The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field).

dasannetworks / h660gw_firmware
Network
Published Oct 1, 2018
CVE-2018-10562
CRITICAL9.8

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

dasannetworks / gpon_router_firmware
Network
Published May 4, 2018
CVE-2018-10561
CRITICAL9.8

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

dasannetworks / gpon_router_firmware
Network
Published May 4, 2018
CVE-2017-18046
CRITICAL9.8

Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi).

dasannetworks / h640x_firmware+2
Network
Published Jan 21, 2018