First published: Thu Mar 28 2019(Updated: )
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teltonika RUT950 Firmware | =r_31.04.89 | |
Teltonika Networks RUT950 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19879 is considered a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2018-19879, upgrade the Teltonika RUT950 firmware to version R_00.05.00.5 or later.
CVE-2018-19879 is associated with insufficient authentication protection in the web interface of Teltonika RTU9XX devices.
CVE-2018-19879 affects users of Teltonika RTU9XX devices running firmware version R_31.04.89 before R_00.05.00.5.
An attacker can exploit CVE-2018-19879 to conduct brute-force login attacks without any restrictions.