Vulnerability Description
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Billion | 5200W-T Firmware | 7.3.8.0 |
| Billion | 5200W-T | - |
| Zyxel | P660Hn-T1A V2 Firmware | 7.3.15.0 |
| Zyxel | P660Hn-T1A V2 | - |
| Zyxel | P660Hn-T1A V1 Firmware | 7.3.15.0 |
| Zyxel | P660Hn-T1A V1 | - |
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40ExploitMailing ListThird Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910ExploitTechnical DescriptionThird Party Advisory
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2017/Jan/40ExploitMailing ListThird Party Advisory
- https://ssd-disclosure.com/index.php/archives/2910ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2017-18372?
CVE-2017-18372 is a vulnerability with a CVSS score of 8.8 (HIGH). The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated us...
How severe is CVE-2017-18372?
CVE-2017-18372 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18372?
Check the references section above for vendor advisories and patch information. Affected products include: Billion 5200W-T Firmware, Billion 5200W-T, Zyxel P660Hn-T1A V2 Firmware, Zyxel P660Hn-T1A V2, Zyxel P660Hn-T1A V1 Firmware.