PatchSiren cyber security CVE debrief
CVE-2017-6884 Zyxel CVE debrief
CVE-2017-6884 is a Zyxel EMG2926 router command injection vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry indicates known exploitation and marks known ransomware campaign use as "Known," so defenders should treat this as an urgent remediation item. CISA added the entry on 2023-09-18 and set a due date of 2023-10-09 for applying mitigations or discontinuing use if mitigations are unavailable.
- Vendor
- Zyxel
- Product
- EMG2926 Routers
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2023-09-18
- Original CVE updated
- 2023-09-18
- Advisory published
- 2023-09-18
- Advisory updated
- 2023-09-18
Who should care
Organizations still using Zyxel EMG2926 routers or related Zyxel EMG2926/Q10A Ethernet CPE, especially security teams, network administrators, asset owners, and incident responders responsible for internet-facing or remotely managed devices.
Technical summary
The supplied corpus identifies the flaw as a command injection vulnerability in Zyxel EMG2926 Routers. No CVSS score was provided in the supplied data, and the corpus does not include exploit mechanics. CISA’s KEV listing confirms the issue is considered exploited in the wild, and the source metadata points defenders to vendor mitigation guidance and an EOL reference if support is no longer available.
Defensive priority
Immediate
Recommended defensive actions
- Review all Zyxel EMG2926 deployments and confirm whether any affected devices remain in service.
- Apply vendor mitigation guidance referenced by CISA as soon as possible.
- If mitigations or patches are unavailable for the deployed model, discontinue use and replace the device.
- Prioritize remediation for externally exposed or remotely administered systems.
- Restrict administrative access and monitor affected devices for unexpected configuration changes or signs of unauthorized command execution.
Evidence notes
CISA’s KEV source item lists CVE-2017-6884 as a Zyxel EMG2926 Routers command injection vulnerability, with dateAdded 2023-09-18, dueDate 2023-10-09, and knownRansomwareCampaignUse marked Known. The source metadata also references a Zyxel security advisory and a ZyxelGuard EOL page, but the supplied resource links do not include those URLs directly. No CVSS score was present in the supplied corpus.
Official resources
-
CVE-2017-6884 CVE record
CVE.org
-
CVE-2017-6884 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
-
Source item URL
cisa_kev
CISA published the KEV listing on 2023-09-18, with remediation due by 2023-10-09. The supplied corpus does not include the original vendor advisory date.