← Back to CVE List
Vulnerability Intelligence Report
Zyxel P660HN-T1A Routers Command Injection Vulnerability

CVE-2017-18368

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:94.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
billion 5200w-t_firmware 7.3.8.0
billion 5200w-t all
zyxel p660hn-t1a_v2_firmware 7.3.15.0
zyxel p660hn-t1a_v2 all
zyxel p660hn-t1a_v1_firmware 7.3.15.0
zyxel p660hn-t1a_v1 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
94.508%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-05-02T00:00:00
Published2019-05-02T16:14:16
Last Updated2025-10-21T23:45:37

LINK COPIED TO CLIPBOARD