PT-2024-38894 · Teltonika Networks · Rutos+1

CVE-2024-8256

·

Published

2024-12-10

·

Updated

2024-12-10

CVSS v4.0

5.9

Medium

VectorAV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Teltonika Networks RUTOS versions 7.0 through 7.7 Teltonika Networks TSWOS versions 1.0 through 1.2
Description: A vulnerability exists due to incorrect permission handling, allowing a lower privileged user with default permissions to access critical device resources via the API.
Recommendations: For Teltonika Networks RUTOS versions 7.0 through 7.7, consider restricting access to critical device resources until a patch is available. For Teltonika Networks TSWOS versions 1.0 through 1.2, consider disabling API access for lower privileged users with default permissions until a fix is released. As a temporary workaround, consider limiting the use of the API to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8256

Affected Products

Rutos
Tswos