CVE-2017-18371
23Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendepss 23%
da publicação à arma0 dias
Publicada no NVD2 de mai.
metasploit26 de dez.
probabilidade de exploração
23%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.
Produtos afetados
n/a · n/aReferências
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txthttps://seclists.org/fulldisclosure/2017/Jan/40https://ssd-disclosure.com/index.php/archives/2910https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/http://www.zyxel.com/support/announcement_unauthenticated.shtml