← Back

CVE-2017-8116

nvd nist
Published: Jul 3, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.

Affected (4)

4 products
Rut900 Firmware
Rut905 Firmware
Rut950 Firmware
Rut955 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 00.03.265
Running on/withPlatform Versions
Teltonika
Rut900
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 00.03.265
Running on/withPlatform Versions
Teltonika
Rut905
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 00.03.265
Running on/withPlatform Versions
Teltonika
Rut950
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 00.03.265
Running on/withPlatform Versions
Teltonika
Rut955
All versions

References (6)

Timeline

No history available yet.