CVE-2017-18368
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zyxel P660HN-T1A Routers Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 95% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
billion: 5200w-t firmware; billion: 5200w-t; zyxel: p660hn-t1a v2 firmware; zyxel: p660hn-t1a v2; zyxel: p660hn-t1a v1 firmware; zyxel: p660hn-t1a v1
קישורים
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonlin… ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40 ExploitMailing ListThird Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910 ExploitTechnical DescriptionThird Party Advisory
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonlin… ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40 ExploitMailing ListThird Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910 ExploitTechnical DescriptionThird Party Advisory
- http://www.zyxel.com/support/announcement_unauthenticated.shtml Broken Link
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wirel… Technical DescriptionThird Party Advisory
- http://www.zyxel.com/support/announcement_unauthenticated.shtml Broken Link
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wirel… Technical DescriptionThird Party Advisory