PT-2025-35168 · Telesquare · Telesquare Tlr-2005Ksh
Qmssdxn
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9603
Qmssdxn
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9603
6.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Telesquare TLR-2005KSH version 1.2.4
Description:
A vulnerability exists in Telesquare TLR-2005KSH version 1.2.4. The issue is related to command injection in the `/cgi-bin/internet.cgi?Command=lanCfg` file through manipulation of the `Hostname` argument. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
Command Injection