← All CVEs

CVE-2018-17532

critical · 9.8

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.

9.8
CVSS
70.7%
EPSS (exploit prob.)
99th
EPSS percentile
2018-10-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
teltonikarut900_firmware< 00.04.233
teltonikarut900all versions
teltonikarut950_firmware< 00.04.233
teltonikarut950all versions
teltonikarut955_firmware< 00.04.233
teltonikarut955all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-17532