CVE-2025-26010: Critical severity Telesquare TLR-2005KSH vulnerability
Published Mar 26, 2025
·Updated
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.
Affected Software
3 affected components
Telesquare TLR-2005KSH
All of the following
Telesquare Tlr-2005ksh Firmware=1.1.4
Telesquare TLR-2005KSH
Event History
Mar 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26010?
CVE-2025-26010 is considered a high severity vulnerability due to the potential for unauthorized password modification.
2
How do I fix CVE-2025-26010?
To fix CVE-2025-26010, apply the latest firmware update from Telesquare that addresses the vulnerability.
3
What systems are affected by CVE-2025-26010?
CVE-2025-26010 affects the Telesquare TLR-2005KSH 1.1.4 firmware.
4
What type of attack does CVE-2025-26010 facilitate?
CVE-2025-26010 enables unauthorized users to modify the passwords of legitimate accounts through the admin.cgi parameter.
5
Is CVE-2025-26010 being actively exploited?
While specific exploitation details may vary, high severity vulnerabilities like CVE-2025-26010 are often targeted shortly after disclosure.