PT-2017-2845 · Teltonika · Teltonika Rut9Xx

Published

2017-04-20

·

Updated

2019-10-03

·

CVE-2017-8116

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Teltonika RUT9XX versions 00.03.265 and earlier
Description The issue is related to inadequate access control in the authentication request, allowing a remote attacker to execute arbitrary commands with root privileges by using shell metacharacters in the username parameter in a login request.
Recommendations For versions 00.03.265 and earlier, consider disabling the login functionality via the management interface until a patch is available. Restrict access to the management interface to minimize the risk of exploitation. Avoid using the username parameter in the affected login request until the issue is resolved.

Exploit

Fix

OS Command Injection

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02125
CVE-2017-8116

Affected Products

Teltonika Rut9Xx