CRITICAL · 9.8

CVE-2018-17532

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input ...

Vulnerability Description

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TeltonikaRut900 Firmware< 00.04.233
TeltonikaRut900-
TeltonikaRut950 Firmware< 00.04.233
TeltonikaRut950-
TeltonikaRut955 Firmware< 00.04.233
TeltonikaRut955-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-17532?

CVE-2018-17532 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input ...

How severe is CVE-2018-17532?

CVE-2018-17532 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-17532?

Check the references section above for vendor advisories and patch information. Affected products include: Teltonika Rut900 Firmware, Teltonika Rut900, Teltonika Rut950 Firmware, Teltonika Rut950, Teltonika Rut955 Firmware.