Vulnerability record · CVE-2017-18368 · published 2 May 2019
CVE-2017-18368: ZyXEL P660HN-T1A Router Remote System Log Command Injection
Billion · 5200w T Firmware
The ZyXEL P660HN-T1A v1 router (TCLinux Fw 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by TrueOnline) contains an OS command injection flaw in the Remote System Log forwarding function. The ViewLog.asp page passes the remote_host parameter to a shell without sanitization, allowing an unauthenticated remote attacker to execute arbitrary commands on the device.
Description
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command injection with CVSS 9.8, KEV listing, and near-maximum EPSS probability makes this an urgent patching or removal priority.
What it is
The ZyXEL P660HN-T1A v1 router (TCLinux Fw 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by TrueOnline) contains an OS command injection flaw in the Remote System Log forwarding function. The ViewLog.asp page passes the remote_host parameter to a shell without sanitization, allowing an unauthenticated remote attacker to execute arbitrary commands on the device.
Impact
An unauthenticated attacker can execute arbitrary OS commands on the router, gaining full control of the device (CVSS 3.1 base 9.8, C:H/I:H/A:H). This enables traffic interception, botnet enrollment, and use of the router as a pivot into the connected network.
Attack surface
Reachable over the network via the ViewLog.asp page with the remote_host parameter; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are required.
Exploitation
CISA added it to the KEV catalog on 2023-08-07 with a 2023-08-28 remediation due date, and EPSS scores it at 0.94425 (99.847th percentile); public exploit code is referenced in the advisory and mailing-list links.
What to do
- Apply the vendor mitigation from the ZyXEL advisory or discontinue use of the affected P660HN-T1A routers if no fix is available, per CISA KEV required action.
- Block or restrict access to the router's web management interface (including ViewLog.asp) from untrusted networks; never expose it to the internet.
- Isolate affected routers on a segmented management VLAN with strict firewall rules limiting who can reach the HTTP interface.
- Replace end-of-life P660HN-T1A units with supported hardware if the vendor no longer provides firmware updates.
- Monitor for and remove any unauthorized configuration changes or unexpected outbound connections from these devices.
Detection
- Inspect HTTP request logs for POST/GET requests to ViewLog.asp containing shell metacharacters (;, |, $(), backticks) in the remote_host parameter.
- Alert on outbound connections from router management IPs to unusual destinations or ports that could indicate command-and-control after exploitation.
- Monitor router configuration and system log settings for unauthorized changes to the remote syslog host.
- Use network IDS signatures targeting known exploit payloads for CVE-2017-18368 against the ViewLog.asp endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-18368 to the Known Exploited Vulnerabilities catalog on 7 August 2023 as "Zyxel P660HN-T1A Routers Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-18368 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-18368), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.