peter bassill · operator
$ cve CVE-2021-45428 JSON

CVE-2021-45428 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 56.9% (pctl 99)

Patch early

A public exploit exists.

Description

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS56.93% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploityes
Published2022-01-03
Last modified2026-06-17

Affected (2)

VendorProduct
telesquaretlr-2005ksh
telesquaretlr-2005ksh firmware

Public exploits

SourceTitleDate
exploit-dbTLR-2005KSH - Arbitrary File Upload2022-05-11

References

→ the Explorer  ·  watch your stack  ·  NVD