CVE-2017-8116: OS Command Injection
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8116?
CVE-2017-8116 has a high severity rating as it allows remote attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2017-8116?
To fix CVE-2017-8116, update the firmware of Teltonika RUT9XX routers to a version later than 00.03.265.
Which Teltonika router models are affected by CVE-2017-8116?
CVE-2017-8116 affects Teltonika RUT900, RUT905, RUT950, and RUT955 models with firmware versions 00.03.265 and earlier.
Can CVE-2017-8116 be exploited remotely?
Yes, CVE-2017-8116 can be exploited remotely by attackers who send crafted login requests.
What type of vulnerability is CVE-2017-8116?
CVE-2017-8116 is classified as a remote code execution vulnerability due to improper input validation in the management interface.