Critical severity9.8NVD Advisory· Published May 2, 2019· Updated Jun 17, 2026
CVE-2017-18369
CVE-2017-18369
Description
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:o:billion:5200w-t_firmware:1.02b:rc5.dt49:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txtnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2017/Jan/40nvdExploitMailing ListThird Party Advisory
- ssd-disclosure.com/index.php/archives/2910nvdExploitTechnical DescriptionThird Party Advisory
News mentions
1- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025