Teltonika Rut900 Firmware vulnerabilities
4 known vulnerabilities affecting teltonika/rut900_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-17532P1CRITICALCVSS 9.8Exploitedfixed in 00.04.2332018-10-15
CVE-2018-17532 [CRITICAL] CWE-78 CVE-2018-17532: Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS com
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
nvd
CVE-2017-8116P2CRITICALCVSS 9.8≤ 00.03.2652017-07-03
CVE-2017-8116 [CRITICAL] CWE-78 CVE-2017-8116: The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and ear
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
nvd
CVE-2018-17534P4MEDIUMCVSS 6.8fixed in 00.04.2332018-10-15
CVE-2018-17534 [MEDIUM] CWE-287 CVE-2018-17534: Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interfac
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
nvd
CVE-2018-17533P4MEDIUMCVSS 6.1fixed in 00.05.01.12018-10-15
CVE-2018-17533 [MEDIUM] CWE-79 CVE-2018-17533: Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabi
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
nvd