CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Aug 3, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Aug 3, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Aug 3, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive. |
1Teltonika Networks 1Trb245 Firmware Nov 21, 2024 Aug 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. |