CVE-2017-18368
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Added 2023-08-07Remediation due 2023-08-28
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
9.8
CVSS
94.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| billion | 5200w-t_firmware | 7.3.8.0 |
| billion | 5200w-t | all versions |
| zyxel | p660hn-t1a_v2_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v2 | all versions |
| zyxel | p660hn-t1a_v1_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v1 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.zyxel.com/support/announcement_unauthenticated.shtml
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt
- https://seclists.org/fulldisclosure/2017/Jan/40
- https://ssd-disclosure.com/index.php/archives/2910
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/
- http://www.zyxel.com/support/announcement_unauthenticated.shtml
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt
- https://seclists.org/fulldisclosure/2017/Jan/40
- https://ssd-disclosure.com/index.php/archives/2910
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-18368
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-18368