HIGH · 8.8

CVE-2017-11361

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because t...

Vulnerability Description

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntenogroupInteno Router Firmware-
IntenogroupInteno Router-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-11361?

CVE-2017-11361 is a vulnerability with a CVSS score of 8.8 (HIGH). Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because t...

How severe is CVE-2017-11361?

CVE-2017-11361 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-11361?

Check the references section above for vendor advisories and patch information. Affected products include: Intenogroup Inteno Router Firmware, Intenogroup Inteno Router.