ZeroHour

CVE-2017-11361

PoC
CVSS 3.0
8.8 high
EPSS
1%p66
Published
()
Modified
Description

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)

Vendors
intenogroup
Products
inteno router firmware
Weakness
CWE-269
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.