CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerability
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the pingip parameter to the expert/maintenance/diagnostic/nslookup URI.
Other sources
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the pingip parameter to the expert/maintenance/diagnostic/nslookup URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-6884?
CVE-2017-6884 is a command injection vulnerability found in Zyxel EMG2926 routers.
How does the command injection vulnerability in Zyxel EMG2926 routers work?
The vulnerability is located in the diagnostic tools, specifically the nslookup function, allowing a malicious user to execute malicious commands on the router.
What is the impact of CVE-2017-6884?
The vulnerability allows an attacker to execute arbitrary commands on the affected Zyxel EMG2926 routers, compromising their security and potentially gaining unauthorized access.
Are there any known exploits for CVE-2017-6884?
Yes, there are known exploitation vectors, including the ping_ip parameter to the expert/maintenance/diagnostic/nslookup function.
How can I fix the command injection vulnerability in Zyxel EMG2926 routers?
Zyxel has released a security advisory with fixes and recommendations for mitigating the vulnerability. Please refer to their official website for detailed instructions.