PT-2019-8305 · Zyxel · Zyxel P660Hn-T1A

Pedro Ribeiro

·

Publicado

2019-05-02

·

Atualizado

2019-10-03

·

CVE-2017-18370

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZyXEL P660HN-T1A v2 version 7.3.37.6
Description The issue is related to a command injection vulnerability in the Remote System Log forwarding function of the router. This function is accessible only by an authenticated user. The vulnerability is specifically located in the logSet.asp page and can be exploited through the ServerIP parameter.
Recommendations For version 7.3.37.6, as a temporary workaround, consider restricting access to the logSet.asp page until a patch is available. Avoid using the ServerIP parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-18370

Produtos afetados

Zyxel P660Hn-T1A