Authentication Bypass in Teltonika RTU9XX Devices
CVE-2018-19879

7.1HIGH

Key Information:

Vendor

Teltonika

Vendor
CVE Published:
28 March 2019

What is CVE-2018-19879?

A security issue has been discovered in the Teltonika RTU9XX series, particularly within the /cgi-bin/luci component. The devices are susceptible to automated login attempts due to inadequate protection of the authentication mechanism. This flaw allows attackers to execute unlimited login attempts, significantly increasing the risk of password cracking and unauthorized access to user accounts.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.