peter bassill · operator
$ cve CVE-2017-18371 JSON

CVE-2017-18371

9.8
CRITICAL · CVSS 3.0 · EPSS 22.5% (pctl 98)

Patch early

EPSS 22.5% — above the 10% action threshold.

Description

The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS22.53% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2019-05-02
Last modified2026-06-17

Affected (6)

VendorProduct
billion5200w-t
billion5200w-t firmware
zyxelp660hn-t1a v1
zyxelp660hn-t1a v1 firmware
zyxelp660hn-t1a v2
zyxelp660hn-t1a v2 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD