CVE-2017-11361
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
17/07/2017
Last modified:
20/04/2025
Description
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:intenogroup:inteno_router_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:intenogroup:inteno_router:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page