XSS Vulnerability in Teltonika Firmware TRB2_R_00.02.02
CVE-2020-5769

5.4MEDIUM

Key Information:

Vendor
CVE Published:
17 July 2020

What is CVE-2020-5769?

The vulnerability in Teltonika firmware TRB2_R_00.02.02 arises from insufficient output sanitization, enabling remote authenticated attackers to execute persistent cross-site scripting (XSS) attacks. By injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section, attackers can exploit this flaw to manipulate user interactions and potentially compromise user data or session information.

Affected Version(s)

Teltonika Gateway TRB245 TRB2_R_00.02.02 firmware

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.