CVE-2021-45428: Critical severity telesquare tlr-2005ksh vulnerability
Published Jan 3, 2022
·Updated
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
Affected Software
4 affected components
Telesquare Tlr-2005ksh Firmware
Telesquare TLR-2005KSH
All of the following
Telesquare Tlr-2005ksh Firmware
Telesquare TLR-2005KSH
Event History
Jan 3, 2022
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45428?
CVE-2021-45428 is classified as a high severity vulnerability due to the risks associated with arbitrary file uploads.
2
How do I fix CVE-2021-45428?
To fix CVE-2021-45428, disable the PUT method on the Telesquare TLR-2005KSH or restrict file upload capabilities.
3
What types of files can be uploaded due to CVE-2021-45428?
CVE-2021-45428 allows the upload of arbitrary files, including potentially harmful HTML and CGI files.
4
Who is affected by CVE-2021-45428?
CVE-2021-45428 affects users of the Telesquare TLR-2005KSH firmware that allows unauthorized file uploads.
5
What kind of attacks can CVE-2021-45428 facilitate?
CVE-2021-45428 can facilitate attacks such as webshell installation and server compromise through arbitrary file uploads.