Back
CVE-2017-18368
CRITICAL
CISA KEV
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
Published: May 2, 2019
Modified: Jun 17, 2026
CWE-78
CWE-78
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v2_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.15.0 |
GitHub Security Advisory GHSA-8hjr-66w2-mg84
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by...
References (11)
- http://www.zyxel.com/support/announcement_unauthenticated.shtml Broken Link
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt Exploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40 Exploit, Mailing List, Third Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910 Exploit, Technical Description, Third Party Advisory
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/ Technical Description, Third Party Advisory
- http://www.zyxel.com/support/announcement_unauthenticated.shtml Broken Link
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt Exploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40 Exploit, Mailing List, Third Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910 Exploit, Technical Description, Third Party Advisory
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/ Technical Description, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-18368 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
94.43%
Top 0% most likely to be exploited
Threat Score
97.5 / 100
CISA Known Exploited
Date Added:
2023-08-07
Due Date:
2023-08-28
Required Action:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Data Sources
NVD
CISA KEV
EPSS
GitHub