CVE-2017-17761

CRITICAL EXPLOITED

Ichano AtHome IP Camera - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-17761 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including SecuriTeam, mirellesilvajs.

AI-analyzed exploit summary The advisory describes three vulnerabilities in Ichano IP Cameras, including hard-coded credentials for telnet and web server access, and an unauthenticated remote code execution flaw via a service on port 1300. The document provides technical details but does not include executable exploit code.

Description

An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.

Exploits (2)

exploitdb WRITEUP
by SecuriTeam · remotehardware
https://www.exploit-db.com/exploits/44048

The advisory describes three vulnerabilities in Ichano IP Cameras, including hard-coded credentials for telnet and web server access, and an unauthenticated remote code execution flaw via a service on port 1300. The document provides technical details but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Rce | Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Ichano IP Cameras (AtHome Camera)
No auth needed
Prerequisites: Network access to the device · Telnet or HTTP access to the camera · Port 1300 accessibility for RCE
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by mirellesilvajs · poc
https://github.com/mirellesilvajs/iot-vuln-lab-cve-2017-17761

This repository contains an educational simulation of an exploit for CVE-2017-17761, focusing on IoT device vulnerabilities. It appears to be a writeup or documentation rather than functional exploit code.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: IoT devices (specific software not specified)
No auth needed
Prerequisites: Access to vulnerable IoT device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102974
Issue Tracking, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3576

Scores

CVSS v3 9.8
EPSS 0.0721
EPSS Percentile 93.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-06-23
Status published
Products (1)
ichano/athome_ip_camera_firmware
Published Dec 19, 2017
Tracked Since Feb 18, 2026