CVE-2017-18368
Zyxel P660HN-T1A Routers Command Injection Vulnerability
Description
CVE-2017-18368 is a critical OS command injection vulnerability in the ZyXEL P660HN-T1A router that allows an unauthenticated attacker to execute arbitrary commands on the device. The vulnerability exists in the Remote System Log forwarding function on the ViewLog.asp page, where the remote_host parameter is susceptible to command injection. This command injection flaw in the ZyXEL P660HN-T1A has been actively exploited in the wild, with CISA adding CVE-2017-18368 to its Known Exploited Vulnerabilities catalog. With an EPSS score of 93.7% placing it in the 99.8th percentile, this vulnerability is heavily targeted by threat actors including Mirai botnet variants.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| billion | 5200w-t firmware | 7.3.8.0 |
| zyxel | p660hn-t1a v2 firmware | 7.3.15.0 |
| zyxel | p660hn-t1a v1 firmware | 7.3.15.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://www.zyxel.com/support/announcement_unauthenticated.shtml(Broken Link)
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt(Exploit, Third Party Advisory)
- https://seclists.org/fulldisclosure/2017/Jan/40(Exploit, Mailing List, Third Party Advisory)
- https://ssd-disclosure.com/index.php/archives/2910(Exploit, Technical Description, Third Party Advisory)
- https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/(Technical Description, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-18368(US Government Resource)
Weakness Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
In the context of CVE-2017-18368, the ZyXEL P660HN-T1A router fails to properly sanitize user input in the remote_host parameter of the Remote System Log configuration function, allowing attackers to inject arbitrary operating system commands. This OS command injection weakness enables unauthenticated remote attackers to execute commands with the privileges of the router's operating system, leading to complete device compromise.
Learn more: CWE-78 — Improper Neutralization of Special Elements used in an OS Command
Impact Analysis
CVE-2017-18368 carries a CVSS v3.1 score of 9.8 (Critical severity), reflecting complete compromise potential across all security dimensions. The vulnerability is remotely exploitable without physical access, easy to exploit with no special conditions needed, requires no authentication, and demands no user interaction — creating a trivially exploitable attack surface on network edge devices. Confidentiality (High): Attackers executing commands on the router can intercept network traffic, extract stored credentials, and access configuration data including Wi-Fi passwords and administrative credentials. Integrity (High): Command injection enables attackers to modify the router's firmware, alter DNS settings for traffic redirection, install persistent backdoors, and enroll the device into botnets. Availability (High): Attackers can disrupt network connectivity, brick the device, or consume its resources as part of DDoS botnets. The EPSS score of 93.7% indicates near-certain exploitation activity, and this vulnerability has been specifically targeted by Mirai botnet variants for mass device recruitment.
Exploit Maturity
Public exploit code is available for CVE-2017-18368 through multiple sources, including a proof-of-concept advisory by Pedro Ribeiro, a full disclosure post on Seclists, and a detailed technical analysis on SSD Disclosure. CISA has confirmed active exploitation in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation deadline of August 28, 2023. The EPSS score of 93.7% (99.8th percentile) indicates near-certain exploitation activity, and Palo Alto Unit 42 research has documented Mirai botnet variants specifically targeting this vulnerability for automated device recruitment.
Remediation
- Apply vendor mitigations or discontinue use. Follow CISA's required action: apply mitigations per ZyXEL's instructions or discontinue use of the product if mitigations are unavailable. Given that the ZyXEL P660HN-T1A is an end-of-life consumer router, replacing the device with a supported model is strongly recommended.
- Update firmware on affected ZyXEL P660HN-T1A v1 and v2 devices to the latest available version. Also check for updates on Billion 5200W-T routers, which share the affected firmware. If no patched firmware is available, the device should be decommissioned.
- Disable remote management and the Remote System Log forwarding function on the router's web interface to eliminate the vulnerable attack surface. Ensure the ViewLog.asp page and the administration interface are not accessible from the WAN side.
- Implement network-level protections by placing the router behind a firewall that blocks inbound access to the management interface. If the device must remain in service, apply strict access control lists to limit management access to trusted IP addresses only.
- Monitor for indicators of compromise including unusual outbound traffic patterns indicative of botnet activity (DDoS participation, scanning of other devices), unexpected DNS configuration changes, and unauthorized firmware modifications on the affected devices.
Technical Details
CVE-2017-18368 exploits an OS command injection weakness (CWE-78) in the ZyXEL P660HN-T1A v1 router running TCLinux firmware version 7.3.15.0 v001 / 3.40(ULM.0)b31, distributed by the Thai ISP TrueOnline. The vulnerability resides in the ViewLog.asp page, specifically in the Remote System Log forwarding function, where the remote_host parameter is passed directly to an operating system command without proper input sanitization or validation. As reflected in the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the attack is network-based with low complexity, requires no authentication or user interaction, and results in complete compromise of confidentiality, integrity, and availability. The affected products include the ZyXEL P660HN-T1A in both v1 and v2 hardware revisions, as well as the Billion 5200W-T router which shares the vulnerable firmware codebase.
Frequently Asked Questions
Is CVE-2017-18368 being actively exploited?
Yes, CVE-2017-18368 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog, and Mirai botnet variants have been documented targeting this vulnerability for automated device recruitment. The EPSS score of 93.7% (99.8th percentile) confirms widespread exploitation activity.
What products are affected by CVE-2017-18368?
CVE-2017-18368 affects the ZyXEL P660HN-T1A router in both v1 and v2 hardware revisions, as well as the Billion 5200W-T router. These are consumer-grade routers that share a vulnerable TCLinux firmware base, distributed primarily by the Thai ISP TrueOnline.
How do I fix CVE-2017-18368?
The recommended fix is to replace the affected ZyXEL P660HN-T1A or Billion 5200W-T router with a currently supported device, as these are end-of-life products. If replacement is not immediately possible, update to the latest firmware, disable remote management and the Remote System Log forwarding function, and restrict WAN access to the management interface. See the Remediation section for detailed steps.
How severe is CVE-2017-18368?
CVE-2017-18368 is rated Critical with a CVSS v3.1 score of 9.8 out of 10. It ranks in the 99.8th percentile for exploitation probability (EPSS score of 93.7%). The vulnerability allows unauthenticated remote command execution on the router, and multiple public exploits and botnet targeting tools are readily available.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.