CVE Vulnerabilities

CVE-2017-11361

Improper Privilege Management

Published: Jul 17, 2017 | Modified: Oct 03, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Inteno routers have a JUCI ACL misconfiguration that allows the user account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the user password might be user or might match the Wi-Fi key.)

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Inteno_router_firmware Intenogroup - (including) - (including)

Potential Mitigations

References