| |
Vulnerability CVE-2017-11361
Published: 2017-07-17
Description: |
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.) |
Type:
CWE-269 (Improper Privilege Management)
CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
9/10 |
10/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
https://neonsea.uk/blog/2017/07/17/cve-2017-11361.html
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|