CVE-2017-11361

HIGH

Inteno Router Firmware - Improper Privilege Management via JUCI ACL Misconfiguration

Title source: llm
STIX 2.1

Description

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://neonsea.uk/blog/2017/07/17/cve-2017-11361.html

Scores

CVSS v3 8.8
EPSS 0.0120
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
intenogroup/inteno_router_firmware
Published Jul 17, 2017
Tracked Since Feb 18, 2026