Sploitus

CVE-2017-17867

5 known exploits for CVE-2017-17867

Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

Affected products
Inteno Iopsys, Openwrt, Odhcpd
Intenogroup Iopsys
≤ 3.14, 4.0
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
9.6% (95th percentile)
Weakness
CWE-732
NVD status
Modified
Published
2018-01-04
CVE-2017-17867 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2017-17867

Proof-of-concept code and exploit modules indexed by Sploitus