CVE-2017-18369: OS Command Injection
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the advremotelog.asp page and can be exploited through the syslogServerAddr parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18369?
CVE-2017-18369 is a command injection vulnerability in the Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline.
How severe is CVE-2017-18369?
CVE-2017-18369 has a severity score of 9.8, which is considered critical.
How does CVE-2017-18369 affect the Billion 5200W-T router?
CVE-2017-18369 affects the Remote System Log forwarding function of the Billion 5200W-T router, allowing an unauthenticated user to execute arbitrary commands.
What is the affected software version of CVE-2017-18369?
The affected software version of CVE-2017-18369 is 1.02b-rc5.dt49.
How can CVE-2017-18369 be exploited?
CVE-2017-18369 can be exploited through the syslogServerAddr parameter in the adv_remotelog.asp page of the Billion 5200W-T router.