CVE-2018-17532
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
Affected (3)
Products: Teltonika: Rut900 Firmware, Rut950 Firmware, Rut955 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 00.04.233 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 00.04.233 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut950 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 00.04.233 |
| Running on/with | Platform Versions |
|---|---|
Teltonika Rut955 | All versions |
References (6)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.