Telesquare
Telesquare Tlr-2005ksh Firmware: vulnerabilidades y CVE
Telesquare Tlr-2005ksh Firmware tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-9603 | Baja (2.1) | 7.6% | — | 29 ago 2025 | A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to… |
| CVE-2025-28361 | Alta (7.5) | 0.46% | — | 26 mar 2025 | Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component. |
| CVE-2025-26011 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword. |
| CVE-2025-26010 | Crítica (9.8) | 0.40% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword. |
| CVE-2025-26009 | Alta (7.5) | 0.37% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi. |
| CVE-2025-26008 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost. |
| CVE-2025-26007 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi. |
| CVE-2025-26006 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest. |
| CVE-2025-26005 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp. |
| CVE-2025-26004 | Crítica (9.8) | 0.44% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns. |
| CVE-2025-26003 | Crítica (9.8) | 0.69% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest. |
| CVE-2025-26002 | Crítica (9.8) | 0.49% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost. |
| CVE-2025-26001 | Alta (7.5) | 0.38% | — | 26 mar 2025 | Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword. |
| CVE-2024-29269 | Alta (8.8) | 6.3% | — | 10 abr 2024 | An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter. |
| CVE-2021-46424 | Crítica (9.1) | 36% | — | 27 abr 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request. |
| CVE-2021-46423 | Media (5.3) | 1.6% | — | 27 abr 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file. |
| CVE-2021-45428 | Crítica (9.8) | 57% | — | 3 ene 2022 | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.