cbcvebase.
CVE-2015-6018
published 2015-12-31

CVE-2015-6018: The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via…

PriorityP279critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
20.62%
97.2th percentile
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.

Affected

1 ranges
VendorProductVersion rangeFixed in
zyxelpmg5318-b20a_firmware<= v100aanc0b5

Detection & IOCsextracted from sources · hover to see the quote

url/diagnostic/diagnostic_general.cgi
command8.8.8.8; cat /etc/shadow
  • Monitor HTTP POST requests to /diagnostic/diagnostic_general.cgi containing shell metacharacters (e.g., semicolons, pipes) in the PingIPAddr parameter, which indicates OS command injection attempts.
  • Alert on multipart/form-data POST requests to the diagnostic CGI endpoint where the PingIPAddr field contains characters beyond a valid IP address (e.g., ';', '|', '`', '$').
  • Successful exploitation results in commands running as root; look for /etc/shadow read attempts or other sensitive file access originating from the web server process.
  • ·Vulnerability is present only on firmware versions prior to 1.00(AANC.2)C0; the specific tested version is V100AANC0b5. Devices already patched to 1.00(AANC.2)C0 or later are not affected.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.