CVE-2017-6884
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A Zyxel home router allows attackers to run arbitrary commands through the diagnostic nslookup tool by injecting malicious input into the ping_ip parameter. This gives attackers complete control over the router.
Command injection vulnerability in Zyxel EMG2926 firmware V1.00(AAQT.4)b8 diagnostic nslookup function allows unauthenticated remote code execution via unsanitized ping_ip parameter in the expert/maintenance/diagnostic/nslookup URI. Attack vector requires network access to the router's web interface; successful exploitation grants arbitrary command execution with router privileges.
The full analysis of this CVE is available in Portuguese →