CVE-2023-2587: XSS
Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously crafted JSON file with an HTML object to trigger the vulnerability. This could allow the attacker to execute scripts in the account context and obtain remote code execution on managed devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2587?
CVE-2023-2587 is classified as a cross-site scripting (XSS) vulnerability, which poses a significant risk to users of the affected systems.
How do I fix CVE-2023-2587?
To fix CVE-2023-2587, upgrade your Teltonika Remote Management System to version 4.10.0 or later.
What are the affected products for CVE-2023-2587?
CVE-2023-2587 affects all versions of Teltonika’s Remote Management System prior to 4.10.0.
Can CVE-2023-2587 be exploited remotely?
Yes, CVE-2023-2587 can be exploited remotely by an attacker who has knowledge of the MAC address and serial number of a connected device.
What types of attacks can CVE-2023-2587 facilitate?
CVE-2023-2587 can facilitate cross-site scripting attacks, allowing attackers to execute malicious scripts in the context of the user's browser.