LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 7, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-18368 to its Known Exploited Vulnerabilities catalog on Aug 7, 2023, with a federal patch deadline of Aug 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host…

CVE-2017-18368 is a command injection vulnerability in Zyxel P660HN-T1A routers. It affects the Remote System Log forwarding function and can be reached by an unauthenticated user through the remote_host parameter on the ViewLog.asp page. Because the flaw allows remote command execution on a network edge device, successful abuse can give an attacker a foothold on the router itself and potentially the networks it serves. Defenders should treat any internet-facing instance of this model as high priority for inventory and remediation.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In this class of flaw, user-controlled input is passed to a system shell or command interpreter without adequate sanitization. According to the CISA summary, the vulnerable code path is the Remote System Log forwarding feature. An unauthenticated attacker supplies a crafted value in the remote_host parameter of the ViewLog.asp page; that value is then incorporated into a command that the router executes. The result is arbitrary command execution in the context of the router process. Exact payload construction and any secondary effects must be confirmed against the vendor advisory; public detail beyond the parameter and page name is limited.

Am I affected? How to find it in your systems

Zyxel P660HN-T1A devices are consumer and small-office DSL routers that commonly sit at the network perimeter. Inventory efforts should focus on:

Telemetry signs of exploitation are limited in public sources. Monitor for unexpected outbound connections originating from the router, anomalous process or command activity if the platform exposes such logs, and repeated unauthenticated requests to ViewLog.asp that contain unusual characters in the remote_host parameter. Correlate any such activity with changes in router configuration or new administrative sessions.

How to remediate

The primary action is to apply the mitigations or firmware update supplied by the vendor, as directed by CISA: “Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.” Obtain the official advisory and image directly from Zyxel, verify integrity, and install during a maintenance window. After patching, re-validate that the Remote System Log forwarding function no longer accepts unauthenticated input and that the ViewLog.asp endpoint behaves as expected.

Additional hardening steps appropriate to this class of device include:

If you can't patch immediately

Until a vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited router vulnerabilities can lead to full network compromise and subsequent data theft. If you believe an affected Zyxel P660HN-T1A may have been compromised, isolate the device, preserve logs, and begin incident-response procedures. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or other information associated with your accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · P660HN-T1A Routers
WeaknessCWE-78
Added to CISA KEVAug 7, 2023
Federal patch deadlineAug 28, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities