High severity8.8NVD Advisory· Published May 2, 2019· Updated Jun 17, 2026
CVE-2017-18373
CVE-2017-18373
Description
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:o:billion:5200w-t_firmware:7.3.8.0:*:*:*:*:*:*:*
- Range: 7.3.8.0 v008 130603
Patches
Vulnerability mechanics
References
3- raw.githubusercontent.com/pedrib/PoC/master/advisories/zyxel_trueonline.txtnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2017/Jan/40nvdExploitMailing ListThird Party Advisory
- ssd-disclosure.com/index.php/archives/2910nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.