Vulnerability record · CVE-2017-18369 · published 2 May 2019
CVE-2017-18369: Billion 5200W-T router command injection in Remote System Log forwarding
Billion · 5200w T Firmware
The Billion 5200W-T 1.02b.rc5.dt49 router, distributed by TrueOnline, contains an OS command injection flaw in the Remote System Log forwarding function on the adv_remotelog.asp page. The syslogServerAddr parameter is passed to a shell without sanitisation, so an unauthenticated remote user can run arbitrary commands on the device. Because the router sits at the network edge, this exposes both the device and the network behind it.
Description
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution on an internet-facing edge device with public exploit code and a very high EPSS score.
What it is
The Billion 5200W-T 1.02b.rc5.dt49 router, distributed by TrueOnline, contains an OS command injection flaw in the Remote System Log forwarding function on the adv_remotelog.asp page. The syslogServerAddr parameter is passed to a shell without sanitisation, so an unauthenticated remote user can run arbitrary commands on the device. Because the router sits at the network edge, this exposes both the device and the network behind it.
Impact
An attacker gains arbitrary command execution with the router's privileges, allowing full compromise of the device, interception or redirection of traffic, and use of the router as a foothold into the internal network. No credentials are needed, so any reachable instance is at risk.
Attack surface
Reached over the network via HTTP against the adv_remotelog.asp page, specifically the syslogServerAddr parameter. The CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description both indicate no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.676 (99.3rd percentile) and all three references are tagged Exploit, including public proof-of-concept advisories, so working exploit code is publicly available.
What to do
- Apply the vendor firmware update for the 5200W-T if one is available; the record does not name a fixed version, so confirm with Billion or TrueOnline.
- If no patch exists, replace the device or disable the Remote System Log forwarding feature and block access to adv_remotelog.asp.
- Restrict management and web interface access to trusted internal networks only; never expose the router's admin pages to the internet.
- Segment or isolate the router from sensitive internal systems until it is patched or replaced.
Detection
- Monitor HTTP requests to /adv_remotelog.asp, especially POSTs with a syslogServerAddr parameter containing shell metacharacters (;, |, `, $(), &&).
- Alert on outbound connections from the router to unexpected hosts or ports that could indicate command-and-control or exfiltration.
- Review router logs and configuration for unexpected changes to syslog or remote logging settings.
- Watch for shell or utility processes spawned by the router's web server, which would indicate command injection.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2017/Jan/40 | ExploitMailing ListThird Party Advisory |
| https://ssd-disclosure.com/index.php/archives/2910 | ExploitTechnical DescriptionThird Party Advisory |
| https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2017/Jan/40 | ExploitMailing ListThird Party Advisory |
| https://ssd-disclosure.com/index.php/archives/2910 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2017-18369 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-18369), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.