Unauthorized Device Registration Vulnerability in Teltonika's Remote Management System
CVE-2023-2586
9CRITICAL
What is CVE-2023-2586?
Teltonika's Remote Management System version 4.14.0 is susceptible to a significant vulnerability that permits unauthorized attackers to register devices that have not been previously registered. This issue arises when users fail to disable the RMS management feature, which is enabled by default. Exploiting this vulnerability could allow attackers to associate registered devices with their own accounts, enabling them to execute various operations, including remote code execution with root privileges through the Task Manager component of the RMS.
Affected Version(s)
Remote Management System 0 < 4.14.0