CVE-2018-17532
9.8
CRITICAL · CVSS 3.0 · EPSS 70.7% (pctl 99)
Patch early
EPSS 70.7% — above the 10% action threshold.
Description
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 70.66% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-10-15 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| teltonika | rut900 |
| teltonika | rut900 firmware |
| teltonika | rut950 |
| teltonika | rut950 firmware |
| teltonika | rut955 |
| teltonika | rut955 firmware |
References
- http://packetstormsecurity.com/files/149777/Teltonika-RUT9XX-Unauthenticated-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2018/Oct/27
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-01_Teltonika_OS_Command_Injection
- http://packetstormsecurity.com/files/149777/Teltonika-RUT9XX-Unauthenticated-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2018/Oct/27
- https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-01_Teltonika_OS_Command_Injection
→ the Explorer · watch your stack · NVD