CVE-2017-18368
billion 5200w-t firmware, zyxel p660hn-t1a v2 firmware, zyxel p660hn-t1a v1 firmware
Published 2 May 2019 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 7 Aug 2023, with a remediation deadline of 28 Aug 2023 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
References
- www.zyxel.com/support/announcement_unauthenticated.shtml · Broken Link
- raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt · Exploit, Third Party Advisory
- seclists.org/fulldisclosure/2017/Jan/40 · Exploit, Mailing List, Third Party Advisory
- ssd-disclosure.com/index.php/archives/2910 · Exploit, Technical Description, Third Party Advisory
- unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/ · Technical Description, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-18368 · US Government Resource