Vulnerabilities > Teltonika > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-05-22 CVE-2023-2586 Unspecified vulnerability in Teltonika Remote Management System 4.14.0
Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform.
network
low complexity
teltonika
critical
9.8
2023-05-22 CVE-2023-32347 Unspecified vulnerability in Teltonika Remote Management System
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspective for device claiming and from the device perspective for authentication.
network
low complexity
teltonika
critical
9.8
2019-03-28 CVE-2018-19879 Improper Restriction of Excessive Authentication Attempts vulnerability in Teltonika Rut950 Firmware R31.04.89
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices.
network
low complexity
teltonika CWE-307
critical
9.8
2018-10-15 CVE-2018-17532 OS Command Injection vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization.
network
low complexity
teltonika CWE-78
critical
9.8
2017-07-03 CVE-2017-8116 OS Command Injection vulnerability in Teltonika products
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
network
low complexity
teltonika CWE-78
critical
9.8