Vulnerabilities > Teltonika > Rut900 Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-10-15 | CVE-2018-17534 | Improper Authentication vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. | 6.8 |
2018-10-15 | CVE-2018-17533 | Cross-site Scripting vulnerability in Teltonika Rut900 Firmware and Rut950 Firmware Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization. | 6.1 |
2018-10-15 | CVE-2018-17532 | OS Command Injection vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. | 9.8 |
2017-07-03 | CVE-2017-8116 | OS Command Injection vulnerability in Teltonika products The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request. | 9.8 |