PT-2019-8304 · Billion · Billion 5200W-T

Pedro Ribeiro

·

Published

2019-05-02

·

Updated

2025-10-14

·

CVE-2017-18369

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Billion 5200W-T version 1.02b.rc5.dt49
Description The issue is related to a command injection vulnerability in the Remote System Log forwarding function. This function is accessible to unauthenticated users and is located in the adv remotelog.asp page. The vulnerability can be exploited through the syslogServerAddr parameter.
Recommendations For version 1.02b.rc5.dt49, as a temporary workaround, consider restricting access to the adv remotelog.asp page until a patch is available. Avoid using the syslogServerAddr parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2017-18369

Affected Products

Billion 5200W-T