OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access.
Conclusion & alert: CVE-2017-9333 is rated Moderate Risk (64.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.27%). Core evidence: EPSS rose +1.43% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.84% | 2.27% | +1.43% |
| 2 | 2026-05-22 | 0.91% | 0.84% | -0.06% |
| 3 | 2025-03-30 | — | 0.91% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openwebif_project | openwebif | 1.2.5 | cpe:2.3:a:openwebif_project:openwebif:1.2.5:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/619 | Issue Tracking Patch Third Party Advisory |
| https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/621 | Issue Tracking Patch Third Party Advisory |