EXPOSURES › CVE-2017-6884
CVE-2017-6884
CRITICAL ⌖ ON CISA KEV · EXPLOITEDZyxel EMG2926 routers suffered a critical command injection flaw in their diagnostic tools that allowed remote attackers to execute arbitrary commands.
The nslookup diagnostic function in Zyxel EMG2926 routers was vulnerable to command injection, enabling attackers to run malicious code on the device. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability that could lead to full device compromise and lateral movement within a network. Organizations must rigorously patch Zyxel hardware and avoid relying on unpatched diagnostic tools.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe failure in Zyxel's vulnerability management and patching processes.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.