RSS   Vulnerabilities for 'Rut950 firmware'   RSS

2019-06-19
 
CVE-2018-19878

CWE-416
 

 
An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.

 
2019-03-28
 
CVE-2018-19879

CWE-255
 

 
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.

 
2017-07-03
 
CVE-2017-8116

CWE-78
 

 
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.

 

 >>> Vendor: Teltonika 4 Products
Rut955 firmware
Rut905 firmware
Rut950 firmware
Rut900 firmware


Copyright 2024, cxsecurity.com

 

Back to Top