CVE-2017-17867
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.
- Affected products
- Inteno Iopsys, Openwrt, Odhcpd
- Intenogroup Iopsys
- ≤ 3.14, 4.0
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 9.6% (95th percentile)
- Weakness
- CWE-732
- NVD status
- Modified
- Published
- 2018-01-04
CVE-2017-17867 at NVD
5 known exploits for CVE-2017-17867
Proof-of-concept code and exploit modules indexed by Sploitus