CVE-2017-6884: Zyxel EMG2926 Routers
EPSS34.6%No. 974 of 1739 in KEV
CVE year2017~6 yrs before listing
Same vendor in KEV13
Same product1
| Field | Value |
|---|---|
| Vendor | Zyxel |
| Product | EMG2926 Routers |
| Name | Zyxel EMG2926 Routers Command Injection Vulnerability |
| Added to KEV | 2023-09-18 |
| US federal due date | 2023-10-09 |
| Ransomware use | Known |
| CWE | CWE-78 |
CISA description
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Zyxel EMG2926 Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18.