CVE-2020-5788: Path Traversal
Relative Path Traversal in Teltonika firmware TRB2R00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Teltonika firmware vulnerability?
The vulnerability ID for this Teltonika firmware vulnerability is CVE-2020-5788.
What is the severity of CVE-2020-5788?
CVE-2020-5788 has a severity rating of 6.5 (high).
How does the Relative Path Traversal vulnerability in Teltonika firmware TRB2_R_00.02.04.3 work?
The Relative Path Traversal vulnerability in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.
What is the affected software and version for CVE-2020-5788?
The affected software and version for CVE-2020-5788 is Teltonika-networks Trb245 Firmware version 00.02.04.03.
Is Teltonika-networks Trb245 vulnerable to CVE-2020-5788?
No, Teltonika-networks Trb245 is not vulnerable to CVE-2020-5788.
How can I fix the Relative Path Traversal vulnerability in Teltonika firmware TRB2_R_00.02.04.3?
Apply the latest firmware update provided by Teltonika Networks to fix the Relative Path Traversal vulnerability in Teltonika firmware TRB2_R_00.02.04.3.
Where can I find more information about CVE-2020-5788?
You can find more information about CVE-2020-5788 at the following link: [https://www.tenable.com/security/research/tra-2020-57](https://www.tenable.com/security/research/tra-2020-57).
What is the related CWE for CVE-2020-5788?
The related CWE for CVE-2020-5788 is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).