← All CVEs

CVE-2017-18368

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2023-08-07Remediation due 2023-08-28

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

9.8
CVSS
94.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
billion5200w-t_firmware7.3.8.0
billion5200w-tall versions
zyxelp660hn-t1a_v2_firmware7.3.15.0
zyxelp660hn-t1a_v2all versions
zyxelp660hn-t1a_v1_firmware7.3.15.0
zyxelp660hn-t1a_v1all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-18368