CVE-2017-17761
CRITICAL EXPLOITEDIchano AtHome IP Camera - Command Injection
Title source: llmExploitation Summary
CVE-2017-17761 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including SecuriTeam, mirellesilvajs.
AI-analyzed exploit summary The advisory describes three vulnerabilities in Ichano IP Cameras, including hard-coded credentials for telnet and web server access, and an unauthenticated remote code execution flaw via a service on port 1300. The document provides technical details but does not include executable exploit code.
Description
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.
Exploits (2)
The advisory describes three vulnerabilities in Ichano IP Cameras, including hard-coded credentials for telnet and web server access, and an unauthenticated remote code execution flaw via a service on port 1300. The document provides technical details but does not include executable exploit code.
This repository contains an educational simulation of an exploit for CVE-2017-17761, focusing on IoT device vulnerabilities. It appears to be a writeup or documentation rather than functional exploit code.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H