CVE-2017-18368
Summary
| CVE | CVE-2017-18368 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-02 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter. |
Risk And Classification
EPSS: 0.945080000 probability, percentile 0.998430000 (date 2026-07-21)
CISA KEV: Listed on 2023-08-07; due 2023-08-28; ransomware use Unknown
Problem Types: CWE-78
CISA Known Exploited Vulnerability
| Vendor | Zyxel |
|---|---|
| Product | P660HN-T1A Routers |
| Name | Zyxel P660HN-T1A Routers Command Injection Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-a-new-variant-of-gafgyt-malware; https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-p660hn-t1a-dsl-cpe; https://nvd.nist.gov/vuln/detail/CVE-2017-18368 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Billion | 5200w-t | - | All | All | All |
| Hardware | Billion | 5200w-t | - | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.15.0 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.15.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.15.0 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.15.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | MISC | raw.githubusercontent.com | Exploit, Third Party Advisory |
| Full Disclosure: Multiple RCE in ZyXEL / Billion / TrueOnline routers | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| New Mirai Variant Targets Enterprise Wireless Presentation & Display Systems | MISC | unit42.paloaltonetworks.com | Technical Description, Third Party Advisory |
| Zyxel statement regarding unauthenticated remote command execution vulnerability | Zyxel | MISC | www.zyxel.com | Broken Link |
| SSD Advisory - ZyXEL / Billion Multiple Vulnerabilities - SSD Secure Disclosure | MISC | ssd-disclosure.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.