← Vulnerability feed

Vulnerability record · CVE-2017-18369 · published 2 May 2019

CVE-2017-18369: Billion 5200W-T router command injection in Remote System Log forwarding

Billion · 5200w T Firmware

The Billion 5200W-T 1.02b.rc5.dt49 router, distributed by TrueOnline, contains an OS command injection flaw in the Remote System Log forwarding function on the adv_remotelog.asp page. The syslogServerAddr parameter is passed to a shell without sanitisation, so an unauthenticated remote user can run arbitrary commands on the device. Because the router sits at the network edge, this exposes both the device and the network behind it.

9.8 CVSS 3.0 Critical EPSS 68% · top 0.7% CWE-78 · OS command injection
9.8CVSS 3.0 base score, v2 10.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution on an internet-facing edge device with public exploit code and a very high EPSS score.

What it is

The Billion 5200W-T 1.02b.rc5.dt49 router, distributed by TrueOnline, contains an OS command injection flaw in the Remote System Log forwarding function on the adv_remotelog.asp page. The syslogServerAddr parameter is passed to a shell without sanitisation, so an unauthenticated remote user can run arbitrary commands on the device. Because the router sits at the network edge, this exposes both the device and the network behind it.

Impact

An attacker gains arbitrary command execution with the router's privileges, allowing full compromise of the device, interception or redirection of traffic, and use of the router as a foothold into the internal network. No credentials are needed, so any reachable instance is at risk.

Attack surface

Reached over the network via HTTP against the adv_remotelog.asp page, specifically the syslogServerAddr parameter. The CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description both indicate no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.676 (99.3rd percentile) and all three references are tagged Exploit, including public proof-of-concept advisories, so working exploit code is publicly available.

What to do

  • Apply the vendor firmware update for the 5200W-T if one is available; the record does not name a fixed version, so confirm with Billion or TrueOnline.
  • If no patch exists, replace the device or disable the Remote System Log forwarding feature and block access to adv_remotelog.asp.
  • Restrict management and web interface access to trusted internal networks only; never expose the router's admin pages to the internet.
  • Segment or isolate the router from sensitive internal systems until it is patched or replaced.

Detection

  • Monitor HTTP requests to /adv_remotelog.asp, especially POSTs with a syslogServerAddr parameter containing shell metacharacters (;, |, `, $(), &&).
  • Alert on outbound connections from the router to unexpected hosts or ports that could indicate command-and-control or exfiltration.
  • Review router logs and configuration for unexpected changes to syslog or remote logging settings.
  • Watch for shell or utility processes spawned by the router's web server, which would indicate command injection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt ExploitThird Party Advisory
https://seclists.org/fulldisclosure/2017/Jan/40 ExploitMailing ListThird Party Advisory
https://ssd-disclosure.com/index.php/archives/2910 ExploitTechnical DescriptionThird Party Advisory
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt ExploitThird Party Advisory
https://seclists.org/fulldisclosure/2017/Jan/40 ExploitMailing ListThird Party Advisory
https://ssd-disclosure.com/index.php/archives/2910 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2017-18369 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-18368ZyXEL P660HN-T1A Router Remote System Log Command InjectionThe ZyXEL P660HN-T1A v1 router (TCLinux Fw 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by TrueOnline) contains an OS command injection flaw in the Re…KEVEPSS 94%analysed9.8CVE-2017-18371Billion 5200w-t firmware hard-coded credentials vulnerabilityThe ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded…EPSS 23%8.8CVE-2017-18372Billion 5200w-t firmware os command injection vulnerabilityThe Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting functi…EPSS 22%8.8CVE-2017-18373Billion 5200w-t firmware hard-coded credentials vulnerabilityThe Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two ha…EPSS 5.4%8.8CVE-2017-18374Billion 5200w-t firmware hard-coded credentials vulnerabilityThe ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, inc…EPSS 5.5%8.8CVE-2017-18370Billion 5200w-t firmware os command injection vulnerabilityThe ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwardi…EPSS 24%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2017-18369), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.