CVE-2017-6884

Executive Summary

Command injection in Zyxel EMG2926 router firmware V1.00(AAQT.4)b8 via the nslookup diagnostic tool allows attackers to execute arbitrary commands (e.g., via ping_ip). Actively exploited in the wild per CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2017-04-06T17:59:00.163 - Last Modified: 2026-10-01T19:17:13.473

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2023-09-18)

Original Description: A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

"I'm a great believer in luck and I find the harder I work, the more I have of it."

— Thomas Jefferson
Source: NVD