Junglewise Threat Intelligence

CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerability

CVE-2017-6884 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-09-18

Vendors: Zyxel.

Executive brief

Zyxel EMG2926 routers contain an OS command injection vulnerability in the diagnostic tools' nslookup function. An authenticated attacker can execute arbitrary commands via the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Affected products

  • Zyxel EMG2926 V1.00(AAQT.4)b8

Timeline

  • 2017-04-06: disclosed: NVD Published Date
  • 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-09: other: CISA KEV due date for remediation