CVE-2021-46424
CRITICAL NUCLEITelesquare TLR-2005KSH 1.0.0 - File Deletion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-46424. PoCs published by Ahmed Alroky. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in TLR-2005KSH by sending a DELETE request to a specific endpoint without authentication. The PoC shows how an attacker can delete files on the target system by manipulating the HTTP request.
Description
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.
Exploits (1)
This exploit demonstrates an arbitrary file deletion vulnerability in TLR-2005KSH by sending a DELETE request to a specific endpoint without authentication. The PoC shows how an attacker can delete files on the target system by manipulating the HTTP request.
Nuclei Templates (1)
http.html:"TLR-2005KSH" || http.html:"tlr-2005ksh"
body="tlr-2005ksh"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H