CVE-2015-6018

CRITICAL ⚠ Exploit

The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.

Affects 1 product across 1 vendor.

BCS8.8
CVSS 3.09.8
EPSS20.6%
Percentile97th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the diagnostic-ping implementation of ZyXEL PMG5318-B20A devices with firmware versions prior to 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands, posing a significant security risk.

BSID: BS-2015-GLOBAL-157463-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-6018?
A critical vulnerability in the diagnostic-ping implementation of ZyXEL PMG5318-B20A devices with firmware versions prior to 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands, posing a significant security risk.
What is the CVSS score for CVE-2015-6018?
CVE-2015-6018 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 20.6%.
Is CVE-2015-6018 actively exploited?
Public exploit available for CVE-2015-6018. Exploitation risk elevated.
How do I remediate CVE-2015-6018?
Priority: IMMEDIATE.
What systems are affected by CVE-2015-6018?
CVE-2015-6018 affects: Zyxel.
Vulnerability Details
CVE IDCVE-2015-6018
BSIDBS-2015-GLOBAL-157463-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2015-12-31
Last Modified2026-06-17
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending a specially crafted request to the device's web interface, specifically targeting the PingIPAddr parameter in the diagnostic-ping functionality. This allows an attacker to inject and execute arbitrary commands with the privileges of the web server process.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Zyxel Pmg5318-B20A Firmware —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 3924 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ Available — Reference
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Zyxel
CVE-2017-7964 10.0 Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and... CVE-2008-1256 10.0 The ZyXEL P-660HW series router has "admin" as its default password, which al... CVE-2008-1255 10.0 The ZyXEL P-660HW series router maintains authentication state by IP address,... CVE-2015-6016 9.8 ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devi... CVE-2008-1160 9.8 ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processe...
View all Zyxel CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →