RSS   Vulnerabilities for 'Iopsys'   RSS

2018-01-04
 
CVE-2017-17867

CWE-732
 

 
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

 

 >>> Vendor: Intenogroup 4 Products
Inteno router firmware
Iopsys
Iopsys firmware
Eg200 firmware


Copyright 2024, cxsecurity.com

 

Back to Top