CVE-2017-18371
Summary
| CVE | CVE-2017-18371 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-02 17:29:00 UTC |
| Updated | 2019-05-03 19:20:00 UTC |
| Description | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Billion | 5200w-t | - | All | All | All |
| Hardware | Billion | 5200w-t | - | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.37.6 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.37.6 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.37.6 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.37.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | MISC | raw.githubusercontent.com | Exploit, Third Party Advisory |
| Full Disclosure: Multiple RCE in ZyXEL / Billion / TrueOnline routers | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| New Mirai Variant Targets Enterprise Wireless Presentation & Display Systems | MISC | unit42.paloaltonetworks.com | Technical Description, Third Party Advisory |
| Zyxel statement regarding unauthenticated remote command execution vulnerability | Zyxel | MISC | www.zyxel.com | Broken Link |
| SSD Advisory - ZyXEL / Billion Multiple Vulnerabilities - SSD Secure Disclosure | MISC | ssd-disclosure.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.