PT-2025-12993 · Telesquare · Telesquare Tlr-2005Ksh
Published
2025-03-26
·
Updated
2025-03-28
·
CVE-2025-26005
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telesquare TLR-2005KSH version 1.1.4
Description
The issue is related to an unauthorized stack overflow vulnerability. This occurs when requesting the "admin.cgi" parameter with
setNtp.Recommendations
For Telesquare TLR-2005KSH version 1.1.4, as a temporary workaround, consider restricting access to the "admin.cgi" parameter until a patch is available. Avoid using the
setNtp parameter in the affected API endpoint until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telesquare Tlr-2005Ksh