CVE-2017-18368Active Exploitation(billion / 5200w-t)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for billion 5200w-t systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-08-28. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 5200w-t
  • 5200w-t_firmware
  • p660hn-t1a_v1
  • p660hn-t1a_v1_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
5200w-t5200w-t_firmwarep660hn-t1a_v1p660hn-t1a_v1_firmwarep660hn-t1a_v2p660hn-t1a_v2_firmware

3 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-25: 1Active Exploitation · 2026-04-25: 1Technical Details · 2026-04-25: 104-25
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting ZyXEL routers (CVE-2017-18368) to deliver #Mirai 2026-04-25 13:41:21 UTC Source IP: 130.12.180.78 🇳🇱 POST /cgi-bin/ViewLog.asp IOCs: hxxp://85.11.167.177/Yboats.arm7 85.11.167.177 🇧🇬 1f6956055553bf37ba73dd32dc50bbaa https://t.co/qH1TiWvCxX

    Post summary

    Attacker activity targeting ZyXEL routers via CVE-2017-18368 is confirmed, with source IP evidence and malicious payload links indicating active exploitation for Mirai deployment.

    00010232
    1.7K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWbillion5200w-t---
OSbillion5200w-t_firmware7.3.8.0--
HWzyxelp660hn-t1a_v1---
OSzyxelp660hn-t1a_v1_firmware7.3.15.0--
HWzyxelp660hn-t1a_v2---
OSzyxelp660hn-t1a_v2_firmware7.3.15.0--

Explore more