Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-8256

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
0
Attacker Value
Unknown

CVE-2023-32350

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
Attacker Value
Unknown

CVE-2023-32349

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.
Attacker Value
Unknown

CVE-2020-5785

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
Attacker Value
Unknown

CVE-2020-5787

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.
Attacker Value
Unknown

CVE-2020-5789

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
Attacker Value
Unknown

CVE-2020-5786

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
Attacker Value
Unknown

CVE-2020-5788

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
Attacker Value
Unknown

CVE-2020-5784

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
Attacker Value
Unknown

CVE-2020-5772

Disclosure Date: August 03, 2020 (last updated February 21, 2025)
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.