peter bassill · operator
$ cve CVE-2018-17532 JSON

CVE-2018-17532

9.8
CRITICAL · CVSS 3.0 · EPSS 70.7% (pctl 99)

Patch early

EPSS 70.7% — above the 10% action threshold.

Description

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS70.66% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2018-10-15
Last modified2026-06-17

Affected (6)

VendorProduct
teltonikarut900
teltonikarut900 firmware
teltonikarut950
teltonikarut950 firmware
teltonikarut955
teltonikarut955 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD