← Vulnerability feed

Vulnerability record · CVE-2017-18368 · published 2 May 2019

CVE-2017-18368: ZyXEL P660HN-T1A Router Remote System Log Command Injection

Billion · 5200w T Firmware

The ZyXEL P660HN-T1A v1 router (TCLinux Fw 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by TrueOnline) contains an OS command injection flaw in the Remote System Log forwarding function. The ViewLog.asp page passes the remote_host parameter to a shell without sanitization, allowing an unauthenticated remote attacker to execute arbitrary commands on the device.

9.8 CVSS 3.1 Critical CISA KEV since 7 Aug 2023 EPSS 94% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
11References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote command injection with CVSS 9.8, KEV listing, and near-maximum EPSS probability makes this an urgent patching or removal priority.

What it is

The ZyXEL P660HN-T1A v1 router (TCLinux Fw 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by TrueOnline) contains an OS command injection flaw in the Remote System Log forwarding function. The ViewLog.asp page passes the remote_host parameter to a shell without sanitization, allowing an unauthenticated remote attacker to execute arbitrary commands on the device.

Impact

An unauthenticated attacker can execute arbitrary OS commands on the router, gaining full control of the device (CVSS 3.1 base 9.8, C:H/I:H/A:H). This enables traffic interception, botnet enrollment, and use of the router as a pivot into the connected network.

Attack surface

Reachable over the network via the ViewLog.asp page with the remote_host parameter; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are required.

Exploitation

CISA added it to the KEV catalog on 2023-08-07 with a 2023-08-28 remediation due date, and EPSS scores it at 0.94425 (99.847th percentile); public exploit code is referenced in the advisory and mailing-list links.

What to do

  • Apply the vendor mitigation from the ZyXEL advisory or discontinue use of the affected P660HN-T1A routers if no fix is available, per CISA KEV required action.
  • Block or restrict access to the router's web management interface (including ViewLog.asp) from untrusted networks; never expose it to the internet.
  • Isolate affected routers on a segmented management VLAN with strict firewall rules limiting who can reach the HTTP interface.
  • Replace end-of-life P660HN-T1A units with supported hardware if the vendor no longer provides firmware updates.
  • Monitor for and remove any unauthorized configuration changes or unexpected outbound connections from these devices.

Detection

  • Inspect HTTP request logs for POST/GET requests to ViewLog.asp containing shell metacharacters (;, |, $(), backticks) in the remote_host parameter.
  • Alert on outbound connections from router management IPs to unusual destinations or ports that could indicate command-and-control after exploitation.
  • Monitor router configuration and system log settings for unauthorized changes to the remote syslog host.
  • Use network IDS signatures targeting known exploit payloads for CVE-2017-18368 against the ViewLog.asp endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-18368 to the Known Exploited Vulnerabilities catalog on 7 August 2023 as "Zyxel P660HN-T1A Routers Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18368 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-18371Billion 5200w-t firmware hard-coded credentials vulnerabilityThe ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded…EPSS 23%9.8CVE-2017-18369Billion 5200W-T router command injection in Remote System Log forwardingThe Billion 5200W-T 1.02b.rc5.dt49 router, distributed by TrueOnline, contains an OS command injection flaw in the Remote System Log forwarding funct…EPSS 68%analysed8.8CVE-2017-18372Billion 5200w-t firmware os command injection vulnerabilityThe Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting functi…EPSS 22%8.8CVE-2017-18373Billion 5200w-t firmware hard-coded credentials vulnerabilityThe Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two ha…EPSS 5.4%8.8CVE-2017-18374Billion 5200w-t firmware hard-coded credentials vulnerabilityThe ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, inc…EPSS 5.5%8.8CVE-2017-18370Billion 5200w-t firmware os command injection vulnerabilityThe ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwardi…EPSS 24%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2017-18368), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.