CVE-2017-8116
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
Affected (4)
Products: Teltonika: Rut900 Firmware, Rut905 Firmware, Rut950 Firmware, Rut955 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 00.03.265 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 00.03.265 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut905 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 00.03.265 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut950 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 00.03.265 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut955 | All versions |
References (6)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.