Teltonika

Remote Management System

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 22.05.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:03:09

Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with al...

  • EPSS 0.78%
  • Veröffentlicht 22.05.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:52

Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then a...

  • EPSS 0.17%
  • Veröffentlicht 22.05.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:53

Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously...

  • EPSS 0.55%
  • Veröffentlicht 22.05.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:53

Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web management services over the cloud proxy. A user can request a web proxy and obtain a URL in the Remo...

  • EPSS 0.16%
  • Veröffentlicht 22.05.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:09

Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of ...

  • EPSS 0.19%
  • Veröffentlicht 22.05.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:03:09

Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspective for device claiming and from the device perspective for authentication. If an attacker obtained t...