CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-09-18. EPSS: 34.6% chance of exploitation in the next 30 days.

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Affected products

  • Zyxel EMG2926 Firmware: version v1.00(aaqt.4)b8 only

Published 2017-04-06. Last modified 2026-10-01.