Server-Side Request Forgery Vulnerability in Teltonika Firmware
CVE-2020-5784

6.5MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2020

What is CVE-2020-5784?

A Server-Side Request Forgery vulnerability exists in Teltonika firmware version TRB2_R_00.02.04.3, allowing low-privileged users to manipulate the application into making HTTP GET requests to arbitrary URLs. This security flaw could potentially be exploited to access sensitive data or perform unauthorized actions on the network.

Affected Version(s)

Teltonika Gateway TRB245 TRB2_R_00.02.04.3 firmware

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.