Back

CVE-2017-18369

CRITICAL

The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.

Published: May 2, 2019 Modified: Jun 17, 2026
CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
billion 5200w-t_firmware 1.02b

GitHub Security Advisory GHSA-phx7-93x9-xx64

The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection...

References (6)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 67.64%

Top 1% most likely to be exploited

Threat Score 59.5 / 100

Data Sources

NVD EPSS GitHub