PT-2017-4255 · Zyxel · Zyxel Emg2926
Trevor Hough
·
Publicado
2017-04-06
·
Atualizado
2025-02-04
·
CVE-2017-6884
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel EMG2926 version V1.00(AAQT.4)b8
Description
A command injection issue was discovered in the diagnostic tools of the Zyxel EMG2926 home router, specifically in the nslookup function. This allows a malicious user to execute arbitrary commands on the router by exploiting various vectors, such as the
ping ip parameter to the "expert/maintenance/diagnostic/nslookup" URI.Recommendations
For Zyxel EMG2926 version V1.00(AAQT.4)b8, consider disabling the nslookup function in the diagnostic tools as a temporary workaround until a patch is available.
Restrict access to the "expert/maintenance/diagnostic/nslookup" URI to minimize the risk of exploitation.
Avoid using the
ping ip parameter in the affected URI until the issue is resolved.Exploit
Correção
OS Command Injection
Special Elements Injection
Improper Neutralization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zyxel Emg2926