Vulnerabilities > Teltonika > Rut950 Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-06-19 CVE-2018-19878 Use After Free vulnerability in Teltonika Rut950 Firmware R31.04.89
An issue was discovered on Teltonika RTU950 R_31.04.89 devices.
network
low complexity
teltonika CWE-416
6.8
2019-03-28 CVE-2018-19879 Improper Restriction of Excessive Authentication Attempts vulnerability in Teltonika Rut950 Firmware R31.04.89
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices.
network
low complexity
teltonika CWE-307
5.0
2018-10-15 CVE-2018-17534 Improper Authentication vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control.
local
low complexity
teltonika CWE-287
7.2
2018-10-15 CVE-2018-17533 Cross-site Scripting vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
network
teltonika CWE-79
4.3
2018-10-15 CVE-2018-17532 OS Command Injection vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization.
network
low complexity
teltonika CWE-78
critical
10.0
2017-07-03 CVE-2017-8116 OS Command Injection vulnerability in Teltonika products
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
network
low complexity
teltonika CWE-78
critical
10.0