Junglewise Threat Intelligence

CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability

CVE-2017-18368 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-08-07

Vendors: Zyxel.

Executive brief

Zyxel P660HN-T1A routers contain an unauthenticated command injection vulnerability in the Remote System Log forwarding function. The flaw exists in the ViewLog.asp page and can be exploited via the remote_host parameter to execute arbitrary OS commands.

Affected products

  • Zyxel P660HN-T1A v1 firmware 7.3.15.0 v001 / 3.40(ULM.0)b31
  • Zyxel P660HN-T1A v2 firmware 7.3.15.0
  • Billion 5200W-T firmware 7.3.8.0

Timeline

  • 2017-01-24: disclosed: Initial public disclosure via Full Disclosure mailing list
  • 2019-05-03: other: Initial NIST NVD analysis published
  • 2023-08-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog