Cross-Site Scripting Vulnerability in Teltonika's Remote Management System
CVE-2023-2587
7.5HIGH
What is CVE-2023-2587?
Teltonika's Remote Management System versions prior to 4.10.0 are susceptible to a cross-site scripting (XSS) vulnerability found in the web interface's main page. An attacker possessing the MAC address and serial number of a connected device can exploit this vulnerability by sending a specially crafted JSON file containing an HTML object. Successful exploitation allows the attacker to execute arbitrary scripts within the account context, potentially leading to remote code execution on devices managed through this system. This security issue underscores the importance of applying the latest updates to safeguard against potential exploitation.
Affected Version(s)
Remote Management System 0 < 4.10.0