RaqibCTI
CVE

CVE-2017-6884

P1⬤ KNOWN RANSOMWARE USE
Zyxel EMG2926 Routers Command Injection Vulnerability
Zyxel · EMG2926 Routers
Date added (CISA)
2023-09-18
Remediation due
2023-10-09
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Source: NVD ↗ · CISA KEV Catalog ↗