First published: Mon Jan 03 2022(Updated: )
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Telesquare TLR-2005KSH | ||
Telesquare TLR-2005KSH Firmware | ||
Telesquare TLR-2005KSH | ||
Telesquare TLR-2005KSH Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45428 is classified as a high severity vulnerability due to the risks associated with arbitrary file uploads.
To fix CVE-2021-45428, disable the PUT method on the Telesquare TLR-2005KSH or restrict file upload capabilities.
CVE-2021-45428 allows the upload of arbitrary files, including potentially harmful HTML and CGI files.
CVE-2021-45428 affects users of the Telesquare TLR-2005KSH firmware that allows unauthorized file uploads.
CVE-2021-45428 can facilitate attacks such as webshell installation and server compromise through arbitrary file uploads.