Unauthorized Device Registration Vulnerability in Teltonika's Remote Management System
CVE-2023-2586

9CRITICAL

Key Information:

Vendor

Teltonika

Vendor
CVE Published:
22 May 2023

What is CVE-2023-2586?

Teltonika's Remote Management System version 4.14.0 is susceptible to a significant vulnerability that permits unauthorized attackers to register devices that have not been previously registered. This issue arises when users fail to disable the RMS management feature, which is enabled by default. Exploiting this vulnerability could allow attackers to associate registered devices with their own accounts, enabling them to execute various operations, including remote code execution with root privileges through the Task Manager component of the RMS.

Affected Version(s)

Remote Management System 0 < 4.14.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Roni Gavrilov
OTORIO
.