{"api_version":"1","generated_at":"2026-07-23T08:46:22+00:00","cve":"CVE-2017-18368","urls":{"html":"https://cve.report/CVE-2017-18368","api":"https://cve.report/api/cve/CVE-2017-18368.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-18368","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-18368"},"summary":{"title":"CVE-2017-18368","description":"The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-05-02 17:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt","name":"https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/fulldisclosure/2017/Jan/40","name":"https://seclists.org/fulldisclosure/2017/Jan/40","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: Multiple RCE in ZyXEL / Billion / TrueOnline routers","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/","name":"https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/","refsource":"MISC","tags":["Technical Description","Third Party Advisory"],"title":"New Mirai Variant Targets Enterprise Wireless Presentation & Display Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zyxel.com/support/announcement_unauthenticated.shtml","name":"http://www.zyxel.com/support/announcement_unauthenticated.shtml","refsource":"MISC","tags":["Broken Link"],"title":"Zyxel statement regarding unauthenticated remote command execution vulnerability | Zyxel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ssd-disclosure.com/index.php/archives/2910","name":"https://ssd-disclosure.com/index.php/archives/2910","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"SSD Advisory - ZyXEL / Billion Multiple Vulnerabilities - SSD Secure Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-18368","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18368","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"18368","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"billion","cpe5":"5200w-t","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"billion","cpe5":"5200w-t","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"billion","cpe5":"5200w-t_firmware","cpe6":"7.3.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"billion","cpe5":"5200w-t_firmware","cpe6":"7.3.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zyxel","cpe5":"p660hn-t1a_v1","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zyxel","cpe5":"p660hn-t1a_v1","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zyxel","cpe5":"p660hn-t1a_v1_firmware","cpe6":"7.3.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zyxel","cpe5":"p660hn-t1a_v1_firmware","cpe6":"7.3.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zyxel","cpe5":"p660hn-t1a_v2","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"zyxel","cpe5":"p660hn-t1a_v2","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zyxel","cpe5":"p660hn-t1a_v2_firmware","cpe6":"7.3.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18368","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"zyxel","cpe5":"p660hn-t1a_v2_firmware","cpe6":"7.3.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2017","cve_id":"18368","cve":"CVE-2017-18368","vendorProject":"Zyxel","product":"P660HN-T1A Routers","vulnerabilityName":"Zyxel P660HN-T1A Routers Command Injection Vulnerability","dateAdded":"2023-08-07","shortDescription":"Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-08-28","knownRansomwareCampaignUse":"Unknown","notes":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-a-new-variant-of-gafgyt-malware; https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerability-in-p660hn-t1a-dsl-cpe; https://nvd.nist.gov/vuln/detail/CVE-2017-18368","cwes":"CWE-78","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2017","cve_id":"18368","cve":"CVE-2017-18368","epss":"0.945080000","percentile":"0.998440000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:32"},"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-18368","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://seclists.org/fulldisclosure/2017/Jan/40","refsource":"MISC","name":"https://seclists.org/fulldisclosure/2017/Jan/40"},{"url":"https://ssd-disclosure.com/index.php/archives/2910","refsource":"MISC","name":"https://ssd-disclosure.com/index.php/archives/2910"},{"url":"https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/","refsource":"MISC","name":"https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/"},{"url":"https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt","refsource":"MISC","name":"https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt"},{"url":"http://www.zyxel.com/support/announcement_unauthenticated.shtml","refsource":"MISC","name":"http://www.zyxel.com/support/announcement_unauthenticated.shtml"}]}},"nvd":{"publishedDate":"2019-05-02 17:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:billion:5200w-t_firmware:7.3.8.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:billion:5200w-t:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:zyxel:p660hn-t1a_v2_firmware:7.3.15.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:zyxel:p660hn-t1a_v2:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:zyxel:p660hn-t1a_v1_firmware:7.3.15.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:zyxel:p660hn-t1a_v1:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"18368","Ordinal":"149998","Title":"CVE-2017-18368","CVE":"CVE-2017-18368","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"18368","Ordinal":"1","NoteData":"The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"18368","Ordinal":"2","NoteData":"2019-05-02","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"18368","Ordinal":"3","NoteData":"2019-05-02","Type":"Other","Title":"Modified"}]}}}