Remote Management System Vulnerability in Teltonika Products
CVE-2023-2588
8.8HIGH
What is CVE-2023-2588?
The Remote Management System by Teltonika, prior to version 4.10.0, is susceptible to an improper access control vulnerability. This issue arises from a feature allowing users to access managed devices' local SSH and web management services via a cloud proxy. A malicious user could generate a URL linked to this service in the Remote Management System's cloud subdomain, which can be shared without requiring authentication to the service. When a victim visits a crafted malicious webpage using this URL, it could lead to a reverse shell, allowing the attacker remote code execution on the victim's device. Immediate attention is recommended to mitigate potential exploitation.
Affected Version(s)
Remote Management System 0 < 4.10.0