CVE-2017-6884
KEV ransomware PoC largeCommand Injection in Zyxel EMG2926 Router Diagnostics
CISA: Zyxel EMG2926 Routers Command Injection Vulnerability
CVE-2017-6884 is an OS command injection flaw (CWE-78) in the diagnostic tools of Zyxel EMG2926 routers, located in the nslookup function. An attacker can trigger it through multiple vectors, notably by supplying a malicious ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI, causing attacker-controlled commands to execute on the router. Successful exploitation yields arbitrary command execution on the gateway, providing a foothold that can be used for further network compromise, including by ransomware operators. Any operator of a Zyxel EMG2926 router is affected, and many of these gateways were deployed through internet service providers. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with known ransomware use, and EPSS estimates a 36.8% probability of exploitation within 30 days (98th percentile).
What to do: Per CISA's required action, apply mitigations per Zyxel's instructions or discontinue use of the product if mitigations are unavailable. Check whether the router's management interface, including the expert/maintenance/diagnostic/nslookup endpoint, is reachable from the WAN or untrusted networks and restrict access to it; monitor devices for signs of command execution or ransomware-related activity. Fixed firmware versions were not specified in the available data, so consult Zyxel's advisory for the appropriate upgrade path.
| Zyxel EMG2926 Routers | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
- Affected
- Zyxel EMG2926 Routers
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- zyxel
- Products
- emg2926 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H