PT-2025-13003 · Telesquare · Telesquare Tlr-2005Ksh

Published

2025-03-26

·

Updated

2025-03-28

·

CVE-2025-26011

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Telesquare TLR-2005KSH version 1.1.4
Description The issue is related to an unauthorized stack overflow when requesting the "admin.cgi" parameter with setUsernamePassword.
Recommendations For Telesquare TLR-2005KSH version 1.1.4, consider restricting access to the admin.cgi parameter to minimize the risk of exploitation. Avoid using the setUsernamePassword parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26011

Affected Products

Telesquare Tlr-2005Ksh