PT-2022-12699 · Telesquare · Telesquare Tlr-2005Ksh

Published

2022-04-27

·

Updated

2022-05-09

·

CVE-2021-46423

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telesquare TLR-2005KSH version 1.0.0
Description The issue allows a remote attacker to download a full configuration file due to an unauthenticated file download vulnerability.
Recommendations For Telesquare TLR-2005KSH version 1.0.0, consider restricting access to sensitive configuration files until a patch is available. As a temporary workaround, limit remote access to the device to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-46423

Affected Products

Telesquare Tlr-2005Ksh