CVE-2017-6884 is a critical command injection vulnerability affecting Zyxel EMG2926 home routers with firmware V1.00(AAQT.4)b8. This flaw, located in the diagnostic tools' nslookup function, allows an authenticated malicious user to execute arbitrary commands on the router by manipulating parameters like ping_ip in specific URIs. With a CVSS score of 8.8 (HIGH) and an EPSS percentile exceeding 99%, this vulnerability carries a severe risk of complete compromise (confidentiality, integrity, and availability). It is actively exploited in the wild, including in known ransomware campaigns, and is listed in CISA's KEV catalog, despite the absence of Metasploit or Nuclei modules. An ExploitDB entry (EDB-41782) confirms public exploit code availability, and the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v1.00\(aaqt.4\)b8CPE matchmatch criteria | cpe:2.3:o:zyxel:emg2926_firmware:v1.00\(aaqt.4\)b8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.