← Back to browse · API

CVE-2017-18368

Severity
CRITICAL
CVSS
9.8
EPSS
0.94508
Risk score
58.08
CISA KEV
Yes
PoC
No
Published
2019-05-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2017-9484, GHSA-8HJR-66W2-MG84
Products
Zyxel:P660HN-T1A Routers, n/a:n/a n/a
Sources
cisa.gov CVE-2017-18368
euvd EUVD-2017-9484

Description

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

References