CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-08-07. EPSS: 94.4% chance of exploitation in the next 30 days.

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

Affected products

  • Billion 5200w-T Firmware: version 7.3.8.0 only
  • Zyxel P660HN-T1A v1 Firmware: version 7.3.15.0 only
  • Zyxel P660HN-T1A v2 Firmware: version 7.3.15.0 only

Published 2019-05-02. Last modified 2026-06-17.