CVE-2017-18370
Summary
| CVE | CVE-2017-18370 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-02 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Billion | 5200w-t | - | All | All | All |
| Hardware | Billion | 5200w-t | - | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.37.6 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.37.6 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.37.6 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.37.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | MISC | raw.githubusercontent.com | Exploit, Third Party Advisory |
| Full Disclosure: Multiple RCE in ZyXEL / Billion / TrueOnline routers | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| New Mirai Variant Targets Enterprise Wireless Presentation & Display Systems | MISC | unit42.paloaltonetworks.com | Technical Description, Third Party Advisory |
| Zyxel statement regarding unauthenticated remote command execution vulnerability | Zyxel | MISC | www.zyxel.com | Broken Link |
| SSD Advisory - ZyXEL / Billion Multiple Vulnerabilities - SSD Secure Disclosure | MISC | ssd-disclosure.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.