High severity8.8NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-11361
CVE-2017-11361
Description
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)
Affected products
1- cpe:2.3:o:intenogroup:inteno_router_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- neonsea.uk/blog/2017/07/17/cve-2017-11361.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.