Intenogroup develops firmware and embedded systems for residential and small-business networking devices, including the IOPSYS firmware platform and router products such as the EG200 line. The observed vulnerability exposure centers on access-control and permission-assignment issues within these firmware distributions, reflecting the challenges of securing embedded device administration and file-system protection. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intenogroup over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10123HIGH p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100. | May 16, 2018 | 8.8 | 45 | NO | YES |
CVE-2017-17867HIGH Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify | Jan 4, 2018 | 8.8 | 40 | NO | YES |
CVE-2018-14533HIGH read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp. | Jul 31, 2018 | 7.8 | 36 | NO | YES |
CVE-2017-11361HIGH Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is some | Jul 17, 2017 | 8.8 | 22 | NO | NO |
CVE-2019-13140MEDIUM Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DE | Sep 16, 2019 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intenogroup.
Media articles that mention a CVE ID that affects a product developed by Intenogroup — matched by CVE ID, not by vendor name.