High severity8.8NVD Advisory· Published May 2, 2019· Updated Jun 17, 2026
CVE-2017-18372
CVE-2017-18372
Description
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: = 7.3.8.0 v008 130603
- cpe:2.3:o:billion:5200w-t_firmware:7.3.8.0:*:*:*:*:*:*:*
- cpe:2.3:o:zyxel:p660hn-t1a_v2_firmware:7.3.15.0:*:*:*:*:*:*:*
- cpe:2.3:o:zyxel:p660hn-t1a_v1_firmware:7.3.15.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txtnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2017/Jan/40nvdExploitMailing ListThird Party Advisory
- ssd-disclosure.com/index.php/archives/2910nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.