First published: Thu May 02 2019(Updated: )
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Billion 5200w-t Firmware | =1.02b-rc5.dt49 | |
Billion 5200W-T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18369 is a command injection vulnerability in the Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline.
CVE-2017-18369 has a severity score of 9.8, which is considered critical.
CVE-2017-18369 affects the Remote System Log forwarding function of the Billion 5200W-T router, allowing an unauthenticated user to execute arbitrary commands.
The affected software version of CVE-2017-18369 is 1.02b-rc5.dt49.
CVE-2017-18369 can be exploited through the syslogServerAddr parameter in the adv_remotelog.asp page of the Billion 5200W-T router.