CVE-2017-8116

EUVD-2017-17078
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
teltonikarut900_firmware
𝑥
≤ 00.03.265
teltonikarut905_firmware
𝑥
≤ 00.03.265
teltonikarut950_firmware
𝑥
≤ 00.03.265
teltonikarut955_firmware
𝑥
≤ 00.03.265
𝑥
= Vulnerable software versions