First published: Thu Oct 01 2020(Updated: )
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teltonika-networks Trb245 Firmware | =00.02.04.03 | |
Teltonika-networks Trb245 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5785.
The severity of CVE-2020-5785 is medium with a CVSS score of 6.1.
The Teltonika firmware version TRB2_R_00.02.04.3 is affected by CVE-2020-5785.
An unauthenticated attacker can exploit CVE-2020-5785 by conducting reflected cross-site scripting using a crafted 'action' or 'pkg_name' parameter.
Yes, Teltonika TRB245 firmware version 00.02.04.03 is vulnerable to CVE-2020-5785.