Vulnerability Description
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teltonika | Rut900 Firmware | < 00.05.01.1 |
| Teltonika | Rut900 | - |
| Teltonika | Rut950 Firmware | < 00.05.01.1 |
| Teltonika | Rut950 | - |
| Teltonika | Rut955 Firmware | < 00.05.01.1 |
| Teltonika | Rut955 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/149781/Teltonika-RUT9XX-Reflected-Cross-SitExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2018/Oct/29ExploitMailing ListThird Party Advisory
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180410-01_TExploitThird Party Advisory
- http://packetstormsecurity.com/files/149781/Teltonika-RUT9XX-Reflected-Cross-SitExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2018/Oct/29ExploitMailing ListThird Party Advisory
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180410-01_TExploitThird Party Advisory
FAQ
What is CVE-2018-17533?
CVE-2018-17533 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
How severe is CVE-2018-17533?
CVE-2018-17533 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17533?
Check the references section above for vendor advisories and patch information. Affected products include: Teltonika Rut900 Firmware, Teltonika Rut900, Teltonika Rut950 Firmware, Teltonika Rut950, Teltonika Rut955 Firmware.