CVE-2017-18374

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:billion:5200w-t_firmware:7.3.8.0:*:*:*:*:*:*:*
cpe:2.3:h:billion:5200w-t:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zyxel:p660hn-t1a_v2_firmware:7.3.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p660hn-t1a_v2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zyxel:p660hn-t1a_v1_firmware:7.3.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:p660hn-t1a_v1:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:19

Type Values Removed Values Added
References () http://www.zyxel.com/support/announcement_unauthenticated.shtml - Broken Link () http://www.zyxel.com/support/announcement_unauthenticated.shtml - Broken Link
References () https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt - Exploit, Third Party Advisory () https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txt - Exploit, Third Party Advisory
References () https://seclists.org/fulldisclosure/2017/Jan/40 - Mailing List, Exploit, Third Party Advisory () https://seclists.org/fulldisclosure/2017/Jan/40 - Exploit, Mailing List, Third Party Advisory
References () https://ssd-disclosure.com/index.php/archives/2910 - Exploit, Technical Description, Third Party Advisory () https://ssd-disclosure.com/index.php/archives/2910 - Exploit, Technical Description, Third Party Advisory
References () https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/ - Technical Description, Third Party Advisory () https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/ - Technical Description, Third Party Advisory

Information

Published : 2019-05-02 17:29

Updated : 2024-11-21 03:19


NVD link : CVE-2017-18374

Mitre link : CVE-2017-18374

CVE.ORG link : CVE-2017-18374


JSON object : View

Products Affected

zyxel

  • p660hn-t1a_v2
  • p660hn-t1a_v2_firmware
  • p660hn-t1a_v1_firmware
  • p660hn-t1a_v1

billion

  • 5200w-t_firmware
  • 5200w-t
CWE
CWE-798

Use of Hard-coded Credentials