CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remotehost parameter.
Other sources
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remotehost parameter of the ViewLog.asp page.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18368?
CVE-2017-18368 is a command injection vulnerability found in the Zyxel P660HN-T1A routers.
How can an attacker exploit CVE-2017-18368?
An attacker can exploit CVE-2017-18368 by using the remote_host parameter of the ViewLog.asp page to inject and execute malicious commands on the router.
Is authentication required to exploit CVE-2017-18368?
No, authentication is not required to exploit CVE-2017-18368.
What is the affected software for CVE-2017-18368?
The affected software for CVE-2017-18368 is the Zyxel P660HN-T1A routers.
Are there any known fixes for CVE-2017-18368?
Yes, Zyxel has released security advisories providing patches and firmware updates to address the command injection vulnerability in the P660HN-T1A routers.