PT-2019-8305 · Zyxel · Zyxel P660Hn-T1A

Pedro Ribeiro

·

Published

2019-05-02

·

Updated

2019-10-03

·

CVE-2017-18370

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZyXEL P660HN-T1A v2 version 7.3.37.6
Description The issue is related to a command injection vulnerability in the Remote System Log forwarding function of the router. This function is accessible only by an authenticated user. The vulnerability is specifically located in the logSet.asp page and can be exploited through the ServerIP parameter.
Recommendations For version 7.3.37.6, as a temporary workaround, consider restricting access to the logSet.asp page until a patch is available. Avoid using the ServerIP parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18370

Affected Products

Zyxel P660Hn-T1A