CVE-2017-17867
HIGHIntenogroup Iopsys < 3.14 - Incorrect Permission Assignment
Title source: ruleDescription
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.
Exploits (1)
References (3)
Scores
CVSS v3
8.8
EPSS
0.1981
EPSS Percentile
95.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (2)
intenogroup/iopsys
4.0
intenogroup/iopsys
2.0 - 3.14
Published
Jan 04, 2018
Tracked Since
Feb 18, 2026