CVE-2017-18374: Billion 5200w-T Firmware
High severity, CVSS 8.8. EPSS: 5.5% chance of exploitation in the next 30 days.
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.
Affected products
- Billion 5200w-T Firmware: version 7.3.8.0 only
- Zyxel P660HN-T1A v1 Firmware: version 7.3.15.0 only
- Zyxel P660HN-T1A v2 Firmware: version 7.3.15.0 only
Published 2019-05-02. Last modified 2026-06-17.