PT-2022-12699 · Telesquare · Telesquare Tlr-2005Ksh
Published
2022-04-27
·
Updated
2022-05-09
·
CVE-2021-46423
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telesquare TLR-2005KSH version 1.0.0
Description
The issue allows a remote attacker to download a full configuration file due to an unauthenticated file download vulnerability.
Recommendations
For Telesquare TLR-2005KSH version 1.0.0, consider restricting access to sensitive configuration files until a patch is available. As a temporary workaround, limit remote access to the device to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Telesquare Tlr-2005Ksh