CVE-2017-8116
Published Jul 3, 2017
Last updated 5 years ago
Overview
- Description
- The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-78
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:teltonika:rut900_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C23F232-784F-43BA-88CA-98A288FD5C2B", "versionEndIncluding": "00.03.265" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:teltonika:rut900:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D9D1E794-1212-43CC-BA30-551EE45FA646" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:teltonika:rut905_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "323FAF90-F8A2-4FFE-B79A-08CB7B56BF73", "versionEndIncluding": "00.03.265" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:teltonika:rut905:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8C45D7FA-FA7F-426C-9905-D6A6ACBE8AC1" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:teltonika:rut950_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AAE86264-F281-42DA-AA35-B6964E430684", "versionEndIncluding": "00.03.265" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:teltonika:rut950:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4CE17C85-9A69-41FB-AB96-0DCAB72309A0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:teltonika:rut955_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF39D487-2CD1-4E9E-8323-6C5764B42B8B", "versionEndIncluding": "00.03.265" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:teltonika:rut955:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6F29C3F1-DFAF-433A-8B1E-4BD2A8DF6C1E" } ], "operator": "OR" } ], "operator": "AND" } ]