← Back to CVE List

CVE-2017-11361

Published: 2017-07-17T17:29Z
Last Modified: 2024-11-21T03:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.) > MITRE Terms of Use apply – see LICENSE‑MITRE.txt