CVE-2018-17534
HIGH 7.2EPSS 0.7%
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
- CVSS v3.0
- 6.8 MEDIUM
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.72% chance of exploitation in the next 30 days, 52th percentile
- Published
- 2018-10-15
- Updated
- 2024-08-05
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/149779/Teltonika-RUT9XX-Missing-Access-Control-To-UA…
- http://seclists.org/fulldisclosure/2018/Oct/28
- sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-02_Teltonika_Incorrect_Access_Co…