nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-6884 CVE-2017-6884
HIGHCISA KEVRansomware
Zyxel EMG2926 Routers Command Injection Vulnerability
Record summary
CVE-2017-6884 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2017-6884 in KEV and reports its use in known ransomware campaigns.
Description
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Sep 18, 2023 · CISA
- VulnCheck KEV
- Listed · Jan 8, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 15, 2023 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EMG2926 RoutersBrowse Zyxel / EMG2926 Routers | CISA | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBZyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command InjectionExploitDB exploitby trevor HoughNot analyzed1 file
References
3cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6884 41782exploit
https://www.exploit-db.com/exploits/41782