Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18370

Опубликовано: 02 мая 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Высокий

Описание

The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:billion:5200w-t_firmware:7.3.8.0:*:*:*:*:*:*:*
cpe:2.3:h:billion:5200w-t:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:zyxel:p660hn-t1a_v2_firmware:7.3.37.6:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p660hn-t1a_v2:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:zyxel:p660hn-t1a_v1_firmware:7.3.37.6:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p660hn-t1a_v1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.75866
Высокий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371.

EPSS

Процентиль: 99%
0.75866
Высокий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78