PT-2017-4255 · Zyxel · Zyxel Emg2926
Trevor Hough
·
Published
2017-04-06
·
Updated
2025-02-04
·
CVE-2017-6884
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel EMG2926 version V1.00(AAQT.4)b8
Description
A command injection issue was discovered in the diagnostic tools of the Zyxel EMG2926 home router, specifically in the nslookup function. This allows a malicious user to execute arbitrary commands on the router by exploiting various vectors, such as the
ping ip parameter to the "expert/maintenance/diagnostic/nslookup" URI.Recommendations
For Zyxel EMG2926 version V1.00(AAQT.4)b8, consider disabling the nslookup function in the diagnostic tools as a temporary workaround until a patch is available.
Restrict access to the "expert/maintenance/diagnostic/nslookup" URI to minimize the risk of exploitation.
Avoid using the
ping ip parameter in the affected URI until the issue is resolved.Exploit
Fix
OS Command Injection
Special Elements Injection
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zyxel Emg2926