Unauthorized Device Registration Vulnerability in Teltonika's Remote Management System
CVE-2023-2586
What is CVE-2023-2586?
Teltonika's Remote Management System version 4.14.0 is susceptible to a significant vulnerability that permits unauthorized attackers to register devices that have not been previously registered. This issue arises when users fail to disable the RMS management feature, which is enabled by default. Exploiting this vulnerability could allow attackers to associate registered devices with their own accounts, enabling them to execute various operations, including remote code execution with root privileges through the Task Manager component of the RMS.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Remote Management System 0 < 4.14.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
