CVE-2018-17532
critical · 9.8Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
9.8
CVSS
70.7%
EPSS (exploit prob.)
99th
EPSS percentile
2018-10-15
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| teltonika | rut900_firmware | < 00.04.233 |
| teltonika | rut900 | all versions |
| teltonika | rut950_firmware | < 00.04.233 |
| teltonika | rut950 | all versions |
| teltonika | rut955_firmware | < 00.04.233 |
| teltonika | rut955 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/149777/Teltonika-RUT9XX-Unauthenticated-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2018/Oct/27
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-01_Teltonika_OS_Command_Injection
- http://packetstormsecurity.com/files/149777/Teltonika-RUT9XX-Unauthenticated-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2018/Oct/27
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-01_Teltonika_OS_Command_Injection
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-17532