PT-2025-12989 · Telesquare · Telesquare Tlr-2005Ksh

Published

2025-03-26

·

Updated

2025-03-28

·

CVE-2025-26002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telesquare TLR-2005KSH version 1.1.4
Description The issue is related to an unauthorized stack overflow when requesting the "admin.cgi" parameter with setSyncTimeHost.
Recommendations For Telesquare TLR-2005KSH version 1.1.4, avoid using the setSyncTimeHost parameter in the "admin.cgi" endpoint until a fix is available. As a temporary workaround, consider restricting access to the "admin.cgi" endpoint to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26002

Affected Products

Telesquare Tlr-2005Ksh