CVE-2018-19879: Critical severity teltonika rut950 firmware vulnerability
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R31.04.89 before R00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19879?
CVE-2018-19879 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2018-19879?
To fix CVE-2018-19879, upgrade the Teltonika RUT950 firmware to version R_00.05.00.5 or later.
What vulnerabilities are associated with CVE-2018-19879?
CVE-2018-19879 is associated with insufficient authentication protection in the web interface of Teltonika RTU9XX devices.
Who is affected by CVE-2018-19879?
CVE-2018-19879 affects users of Teltonika RTU9XX devices running firmware version R_31.04.89 before R_00.05.00.5.
What kind of attacks can be performed due to CVE-2018-19879?
An attacker can exploit CVE-2018-19879 to conduct brute-force login attacks without any restrictions.