Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.4%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
ModificadaMedia (6.5)1.2%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
ModificadaMedia (6.5)1.7%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.
ModificadaAlta (8.8)8.6%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
ModificadaMedia (6.1)0.74%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
ModificadaMedia (6.5)0.68%—Teltonika-networks Trb245 Firmware1/10/202017/6/2026
Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.
ModificadaAlta (8.8)0.99%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
ModificadaAlta (7.5)1.1%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.
ModificadaAlta (7.5)2.0%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
ModificadaAlta (8.8)0.69%—Teltonika-networks Trb245 Firmware3/8/202017/6/2026
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
ModificadaMedia (5.4)0.64%—Teltonika-networks Gateway Trb245 Firmware17/7/202017/6/2026
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.
ModificadaMedia (6.5)1.2%—Teltonika Rut950 Firmware19/6/201917/6/2026
An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this…
ModificadaCrítica (9.8)1.3%—Teltonika Rut950 Firmware28/3/201917/6/2026
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an…
ModificadaMedia (6.8)0.72%—Teltonika Rut900 FirmwareTeltonika Rut950 FirmwareTeltonika Rut955 Firmware15/10/201817/6/2026
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
ModificadaMedia (6.1)2.0%—Teltonika Rut900 FirmwareTeltonika Rut950 FirmwareTeltonika Rut955 Firmware15/10/201817/6/2026
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
ModificadaCrítica (9.8)71%—Teltonika Rut900 FirmwareTeltonika Rut950 FirmwareTeltonika Rut955 Firmware15/10/201817/6/2026
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.
ModificadaCrítica (9.8)4.5%—Teltonika Rut900 FirmwareTeltonika Rut905 FirmwareTeltonika Rut950 FirmwareTeltonika Rut955 Firmware3/7/201717/6/2026
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.