CVE-2017-8116
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.52% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- teltonika/rut900 firmware · teltonika/rut905 firmware · teltonika/rut950 firmware · teltonika/rut955 firmware
- Source
- cve@mitre.org
References
- https://github.com/nettitude/metasploit-modules/blob/master/teltonika_add_user.rbExploit, Third Party Advisory
- https://github.com/nettitude/metasploit-modules/blob/master/teltonika_cmd_exec.rbExploit, Third Party Advisory
- https://labs.nettitude.com/blog/cve-2017-8116-teltonika-router-unauthenticated-remote-code-execution/Third Party Advisory
- https://github.com/nettitude/metasploit-modules/blob/master/teltonika_add_user.rbExploit, Third Party Advisory
- https://github.com/nettitude/metasploit-modules/blob/master/teltonika_cmd_exec.rbExploit, Third Party Advisory
- https://labs.nettitude.com/blog/cve-2017-8116-teltonika-router-unauthenticated-remote-code-execution/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.