VendorsTeltonikarut900_firmwareall versions
Vulnerabilities

Teltonika RUT900 FIRMWARE

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-17532
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
Published 2018-10-15 · Modified
10.0EPSS 0.707
CVE-2017-8116
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
Published 2017-07-03 · Modified
10.0EPSS 0.045
CVE-2018-17534
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
Published 2018-10-15 · Modified
7.2EPSS 0.007
CVE-2018-17533
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
Published 2018-10-15 · Modified
6.1EPSS 0.020