CVE-2020-5785: XSS
Published Oct 1, 2020
·Updated
Insufficient output sanitization in Teltonika firmware TRB2R00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkgname’ parameter.
Affected Software
2 affected components
Teltonika-networks Trb245 Firmware=00.02.04.03
Teltonika-networks Trb245
Event History
Oct 1, 2020
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5785.
2
What is the severity of CVE-2020-5785?
The severity of CVE-2020-5785 is medium with a CVSS score of 6.1.
3
What software is affected by CVE-2020-5785?
The Teltonika firmware version TRB2_R_00.02.04.3 is affected by CVE-2020-5785.
4
How can an attacker exploit CVE-2020-5785?
An unauthenticated attacker can exploit CVE-2020-5785 by conducting reflected cross-site scripting using a crafted 'action' or 'pkg_name' parameter.
5
Is Teltonika TRB245 firmware version 00.02.04.03 vulnerable to CVE-2020-5785?
Yes, Teltonika TRB245 firmware version 00.02.04.03 is vulnerable to CVE-2020-5785.