ZeroHour
Security Affairspublished ()ingested @securityaffairs

Gafgyt botnet is targeting EoL Zyxel routers

highMalware exploited in the wildimportance 60CVE-2017-18368CVE-2017-18363

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-18368
Unauthenticated OS Command Injection in Zyxel/Billion TrueOnline Routers

CVE-2017-18368 is a critical (CVSS 9.8) unauthenticated OS command injection (CWE-78) in the Remote System Log forwarding function of Zyxel P660HN-T1A (v1 and v2) and Billion 5200W-T routers distributed by Thailand ISP TrueOnline. An unauthenticated attacker who can reach the router's web management interface sends a crafted remote_host parameter to the ViewLog.asp page, with no credentials or user interaction required. Successful injection executes arbitrary operating-system commands on the device, giving the attacker full control of the router (e.g., botnet recruitment, traffic/DNS manipulation, or pivoting into the subscriber's LAN). Only TrueOnline-issued units of these models are affected, meaning Thai broadband subscribers deployed with this CPE. The flaw is in CISA's KEV catalog (added 2023-08-07), carries a 94.4% EPSS (100th percentile), and related reporting shows IoT botnets (e.g., Gafgyt campaigns against End-of-Life Zyxel routers and multi-exploit campaigns like RondoDox) actively targeting such devices.

Do: Update affected routers to the latest firmware available from Zyxel/Billion or via TrueOnline's ISP update process, noting these models are End-of-Life so hardware replacement is the durable fix. Until patched, restrict or disable WAN-side access to the router's web management interface (the flaw is reachable unauthenticated via ViewLog.asp) and audit devices for signs of botnet compromise. Per the CISA KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.894% KEV PoC ×3
  • Zyxel P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 (TrueOnline-distributed firmware; model listed broadly as affected by CISA)
  • Zyxel P660HN-T1A v2
  • Billion 5200W-T
mass≈1 million (order-of-magnitude estimate) TrueOnline-issued devices, of which thousands to tens of thousands expose the management interface to the internet at…
Full article312 words · extracted from securityaffairs.com · click to collapse

Researchers warn that the Gafgyt botnet is actively exploiting a vulnerability impacting the end-of-life Zyxel P660HN-T1A router.

A variant of the Gafgyt botnet is actively attempting to exploit a vulnerability, tracked as CVE-2017-18368 (CVSS v3: 9.8), impacting the end-of-life Zyxel P660HN-T1A router.

The flaw is a command injection vulnerability that resides in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

The vulnerability impacts devices running firmware versions 7.3.15.0 v001/3.40(ULM.0)b31 or older.

Zyxel addressed the vulnerability in 2017 with the release of new firmware, however, the vendor warned that a Gafgyt variant was exploiting the flaw in 2019.

Now Fortinet published an outbreak alert to warn of a surge in attacks targeting the end-of-life routers in the wild.

“Aug 7, 2023: FortiGuard Labs continue to see attack attempts targeting the 2017 vulnerability and has blocked attack attemtps of over thousands of unique IPS devices over the last month.” reads the alert.

According the following chart, Fortinet is observing an average of 7,300 attacks per day attempting to exploit the flaw since July 2023.

Gafgyt botnet zyxel

US CISA also added the vulnerability to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to fix this flaw by August 28, 2023.

“Zyxel recently became aware of CVE-2017-18368 being listed on the CISA Known Exploited Vulnerabilities (KEV) catalog; however, Zyxel provided a patch for the mentioned customized P660HN-T1A in 2017. Additionally, the P660HN-T1A running the latest generic firmware, version 3.40(BYF.11), is not affected by CVE-2017-18363. Please also note that the P660HN-T1A reached end-of-life several years ago; therefore, we strongly recommend that users replace it with a newer-generation product for optimal protection.” reads a new advisory published by the vendor.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Gafgyt botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/149417/cyber-crime/gafgyt-botnet-targets-zyxel-p660hn-t1a-routers.html