Record summary

CVE-2017-17867 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBIopsys Router - 'dhcp' Remote Code ExecutionExploitDB exploitby neonseaNot analyzed1 file
ExploitDB

PoC details

References

5