CVE-2017-18372: Billion 5200w-T Firmware
High severity, CVSS 8.8. EPSS: 21.9% chance of exploitation in the next 30 days.
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.
Affected products
- Billion 5200w-T Firmware: version 7.3.8.0 only
- Zyxel P660HN-T1A v1 Firmware: version 7.3.15.0 only
- Zyxel P660HN-T1A v2 Firmware: version 7.3.15.0 only
Published 2019-05-02. Last modified 2026-06-17.