PT-2018-6585 · Openwrt+1 · Openwrt+2

Neonsea

·

Published

2018-01-04

·

Updated

2019-10-03

·

CVE-2017-17867

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Inteno iopsys versions 2.0 through 3.14 Inteno iopsys version 4.0
Description: The issue allows remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration. This can be done to specify an arbitrary program, such as one located on an SMB share. The problem exists due to the improper use of the /etc/uci-defaults directory, which fails to secure the OpenWrt configuration.
Recommendations: For Inteno iopsys versions 2.0 through 3.14, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt. For Inteno iopsys version 4.0, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt. As a temporary workaround, consider restricting access to the odhcpd configuration to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17867

Affected Products

Inteno Iopsys
Openwrt
Odhcpd