PT-2018-6585 · Openwrt+1 · Openwrt+2
Neonsea
·
Published
2018-01-04
·
Updated
2019-10-03
·
CVE-2017-17867
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Inteno iopsys versions 2.0 through 3.14
Inteno iopsys version 4.0
Description:
The issue allows remote authenticated users to execute arbitrary OS commands by modifying the
leasetrigger field in the odhcpd configuration. This can be done to specify an arbitrary program, such as one located on an SMB share. The problem exists due to the improper use of the /etc/uci-defaults directory, which fails to secure the OpenWrt configuration.Recommendations:
For Inteno iopsys versions 2.0 through 3.14, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt.
For Inteno iopsys version 4.0, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt.
As a temporary workaround, consider restricting access to the odhcpd configuration to minimize the risk of exploitation.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inteno Iopsys
Openwrt
Odhcpd