Back

HIGH KEV Used in ransomware campaigns

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8

Published Apr 6, 2017 ·Due Oct 9, 2023

Description

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (6)
  1. CISA ADP
    • SSVC technical impact changed from partial to total
  2. CISA ADP
    • SSVC technical impact changed from total to partial
  3. CISA ADP
    • SSVC technical impact changed from partial to total
  4. CISA ADP
    • SSVC technical impact changed from total to partial
  5. CISA ADP
    • SSVC technical impact changed from partial to total
  6. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 6, 2017
Updated Oct 1, 2026
Reserved Mar 14, 2017
CISA Vulnrichment
Updated Aug 4, 2026
NVD
Status Analyzed
Modified Aug 4, 2026
Red Hat
Severity n/a
Public date n/a