CVE-2018-17532

Scores

EPSS

0.777medium77.7%
0%20%40%60%80%100%

Percentile: 77.7%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Related Vulnerabilities

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: rut900_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:teltonika:rut900_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "00.04.233",          "vulnerable"...

Source: nvd

Type: Configuration

Vendor: *

Product: rut950_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:teltonika:rut950_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "00.04.233",          "vulnerable"...

Source: nvd

Type: Configuration

Vendor: *

Product: rut955_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:teltonika:rut955_firmware:*:*:*:*:*:*:*:*",          "versionEndExcluding": "00.04.233",          "vulnerable"...

Source: nvd

End of list