CVE-2017-18374
Summary
| CVE | CVE-2017-18374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-02 17:29:00 UTC |
| Updated | 2019-05-03 19:29:00 UTC |
| Description | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Billion | 5200w-t | - | All | All | All |
| Hardware | Billion | 5200w-t | - | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Operating System | Billion | 5200w-t Firmware | 7.3.8.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V1 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.15.0 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V1 Firmware | 7.3.15.0 | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Hardware | Zyxel | P660hn-t1a V2 | - | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.15.0 | All | All | All |
| Operating System | Zyxel | P660hn-t1a V2 Firmware | 7.3.15.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | MISC | raw.githubusercontent.com | Exploit, Third Party Advisory |
| Full Disclosure: Multiple RCE in ZyXEL / Billion / TrueOnline routers | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| New Mirai Variant Targets Enterprise Wireless Presentation & Display Systems | MISC | unit42.paloaltonetworks.com | Technical Description, Third Party Advisory |
| Zyxel statement regarding unauthenticated remote command execution vulnerability | Zyxel | MISC | www.zyxel.com | Broken Link |
| SSD Advisory - ZyXEL / Billion Multiple Vulnerabilities - SSD Secure Disclosure | MISC | ssd-disclosure.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.