ZeroHour

CVE-2017-6884

KEV ransomware PoC large

Command Injection in Zyxel EMG2926 Router Diagnostics

CISA: Zyxel EMG2926 Routers Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
37%p98
Published
()
KEV added
AI analysis

CVE-2017-6884 is an OS command injection flaw (CWE-78) in the diagnostic tools of Zyxel EMG2926 routers, located in the nslookup function. An attacker can trigger it through multiple vectors, notably by supplying a malicious ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI, causing attacker-controlled commands to execute on the router. Successful exploitation yields arbitrary command execution on the gateway, providing a foothold that can be used for further network compromise, including by ransomware operators. Any operator of a Zyxel EMG2926 router is affected, and many of these gateways were deployed through internet service providers. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with known ransomware use, and EPSS estimates a 36.8% probability of exploitation within 30 days (98th percentile).

What to do: Per CISA's required action, apply mitigations per Zyxel's instructions or discontinue use of the product if mitigations are unavailable. Check whether the router's management interface, including the expert/maintenance/diagnostic/nslookup endpoint, is reachable from the WAN or untrusted networks and restrict access to it; monitor devices for signs of command execution or ransomware-related activity. Fixed firmware versions were not specified in the available data, so consult Zyxel's advisory for the appropriate upgrade path.

Affected
Zyxel EMG2926 Routers
Estimated exposure
largetens of thousands of deployed EMG2926 gateways, plausibly 10,000-100,000 affected systems; exact count unknown — The EMG2926 is an ISP-bundled gateway with deployment patterns suggesting tens of thousands of units in the field, though only a subset expose the diagnostics management interface to untrusted networks, and no public scan counts were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

CISA Known Exploited Vulnerability
Affected
Zyxel EMG2926 Routers
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
zyxel
Products
emg2926 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news