CVE-2018-17533

MEDIUM

Teltonika RUT9XX <00.05.01.1 - XSS

Title source: llm
STIX 2.1

Description

Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.

References (3)

Core 3
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Oct/29

Scores

CVSS v3 6.1
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
teltonika/rut900_firmware < 00.05.01.1
teltonika/rut950_firmware < 00.05.01.1
teltonika/rut955_firmware < 00.05.01.1
Published Oct 15, 2018
Tracked Since Feb 18, 2026