Executive brief
Zyxel EMG2926 routers contain an OS command injection vulnerability in the diagnostic tools' nslookup function. An authenticated attacker can execute arbitrary commands via the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Affected products
- Zyxel EMG2926 V1.00(AAQT.4)b8
Timeline
- 2017-04-06: disclosed: NVD Published Date
- 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-09: other: CISA KEV due date for remediation