VYPR
High severity8.8NVD Advisory· Published Jan 4, 2018· Updated Jun 17, 2026

CVE-2017-17867

CVE-2017-17867

Description

Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Inteno/iopsys3 versions
    cpe:2.3:h:intenogroup:iopsys:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:h:intenogroup:iopsys:*:*:*:*:*:*:*:*range: >=2.0,<=3.14
    • cpe:2.3:h:intenogroup:iopsys:4.0:*:*:*:*:*:*:*
    • (no CPE)range: 2.0-3.14, 4.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.