← Back

Teltonika Networks

teltonika-networks

14 CVEs • 40 products

Products (40)

Click to collapse
Toggle
Trb245
trb245
Rut200
rut200
Rut240
rut240
Rut241
rut241
Rut300
rut300
Rut360
rut360
Rut901
rut901
Rut950
rut950
Rut951
rut951
Rut955
rut955
Rut956
rut956
Rutx08
rutx08
Rutx09
rutx09
Rutx10
rutx10
Rutx11
rutx11
Rutx12
rutx12
Rutx14
rutx14
Rutx50
rutx50
Rutxr1
rutxr1

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Teltonika Networks
1Rut240 Firmware
May 30, 2025
Feb 17, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows that they are only available on the LAN i...Show more
Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows that they are only available on the LAN interface.Show less
1Teltonika Networks
18Rut200 Firmware
Rut240 FirmwareRut241 Firmware+15 more
Nov 21, 2024
May 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function t...Show more
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload. Show less
1Teltonika Networks
18Rut200 Firmware
Rut240 FirmwareRut241 Firmware+15 more
Nov 21, 2024
May 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external con...Show more
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution. Show less
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Oct 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Aug 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Aug 3, 2020
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Aug 3, 2020
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
1Teltonika Networks
1Trb245 Firmware
Nov 21, 2024
Aug 3, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
1Teltonika Networks
1Gateway Trb245 Firmware
Nov 21, 2024
Jul 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'UR...Show more
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.Show less