Vulnerabilities > Teltonika > Rut955 Firmware

DATE CVE VULNERABILITY TITLE RISK
2018-10-15 CVE-2018-17534 Improper Authentication vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control.
local
low complexity
teltonika CWE-287
7.2
2018-10-15 CVE-2018-17533 Cross-site Scripting vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
network
teltonika CWE-79
4.3
2018-10-15 CVE-2018-17532 OS Command Injection vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization.
network
low complexity
teltonika CWE-78
critical
10.0
2017-07-03 CVE-2017-8116 OS Command Injection vulnerability in Teltonika products
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
network
low complexity
teltonika CWE-78
critical
10.0