CVE-2017-18373: Command Injection
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18373?
CVE-2017-18373 refers to a vulnerability in the Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline.
What is the severity of CVE-2017-18373?
CVE-2017-18373 has a severity rating of 8.8 (critical).
What is the affected software for CVE-2017-18373?
The affected software for CVE-2017-18373 is the Billion 5200W-T TCLinux Fw version 7.3.8.0.
What are the default passwords associated with CVE-2017-18373?
CVE-2017-18373 has three user accounts with default passwords: one with the username true and password true, and another with the username user3 and a long password.
Are there any known fixes for CVE-2017-18373?
At this time, there are no known fixes for CVE-2017-18373. It is recommended to contact the vendor for further assistance.