TrueOnline.ZyXEL.P660HN.V1.Unauthenticated.Command.Injection

description-logoDescription

This indicates an attack attempt against a Code Injection vulnerability in ZyXEL P660HN-T router.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted HTTP request. A remote attacker may be able to exploit this to execute arbitrary code on the affected systems.

description-logoOutbreak Alert

A command injection vulnerability (Zyxel P660HN-T1A v1) in the Remote System Log forwarder function of firmware version 3.40 (ULM.0) b3 could allow a remote unauthenticated attacker to execute some OS commands by sending a crafted HTTP request.

View the full Outbreak Alert Report

affected-products-logoAffected Products

ZyXEL P660HN-T v1

Impact logoImpact

System Compromise: Remote attacker can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2022-04-26 20.304 Sig Added
2020-05-19 15.846 Sig Added