Reflected Cross-Site Scripting Vulnerability in Teltonika Firmware
CVE-2020-5785
6.1MEDIUM
What is CVE-2020-5785?
A reflected cross-site scripting vulnerability exists in Teltonika's firmware TRB2_R_00.02.04.3 due to insufficient output sanitization. This flaw allows attackers to craft malicious requests with specific parameters, such as āactionā or āpkg_nameā, enabling them to inject harmful scripts. If exploited, this vulnerability could permit unauthorized users to execute scripts in a victim's browser session, compromising sensitive information and web application integrity.
Affected Version(s)
Teltonika Gateway TRB245 TRB2_R_00.02.04.3 firmware