Vulnerability record · CVE-2017-6884 · published 6 April 2017
CVE-2017-6884: Zyxel EMG2926 router nslookup command injection
Zyxel · Emg2926 Firmware
The Zyxel EMG2926 home router firmware V1.00(AAQT.4)b8 fails to sanitize input to the diagnostic nslookup function, allowing OS command injection. An attacker who can reach the diagnostic interface can run arbitrary commands on the router, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.
Description
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a public exploit, and carries a high EPSS score, so exploitation is both proven and likely.
What it is
The Zyxel EMG2926 home router firmware V1.00(AAQT.4)b8 fails to sanitize input to the diagnostic nslookup function, allowing OS command injection. An attacker who can reach the diagnostic interface can run arbitrary commands on the router, which is why this flaw was added to CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker gains arbitrary command execution on the router, enabling full device compromise, traffic interception or redirection, and use of the router as a foothold into the connected network.
Attack surface
Reached over the network via the expert/maintenance/diagnostic/nslookup URI, for example through the ping_ip parameter. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so some level of access or authentication is needed rather than none.
Exploitation
CISA added it to KEV on 2023-09-18 with a 2023-10-09 remediation due date and flags known ransomware campaign use; EPSS is 0.36769 (98.4th percentile) and a public Exploit-DB proof of concept exists.
What to do
- Apply the vendor's patch or mitigation for the EMG2926 diagnostic nslookup command injection; if none is available, discontinue use of the device per CISA guidance.
- Restrict access to the router's administrative and diagnostic interfaces to trusted management networks only.
- Change default administrative credentials and disable remote management where it is not required.
- Replace end-of-life EMG2926 units that no longer receive firmware updates.
- Monitor for and block outbound traffic from router management interfaces to unexpected destinations.
Detection
- Inspect router and web logs for requests to the expert/maintenance/diagnostic/nslookup URI, especially with shell metacharacters in the ping_ip parameter.
- Alert on unexpected processes or outbound connections originating from the router's management plane.
- Hunt for anomalous DNS or nslookup activity from router management addresses that does not match normal administrative behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6884 to the Known Exploited Vulnerabilities catalog on 18 September 2023 as "Zyxel EMG2926 Routers Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/41782/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41782/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6884 | US Government Resource |
Track CVE-2017-6884 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6884), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.