CVE-2017-8116

The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
teltonikarut900_firmware
𝑥
≤ 00.03.265
teltonikarut905_firmware
𝑥
≤ 00.03.265
teltonikarut950_firmware
𝑥
≤ 00.03.265
teltonikarut955_firmware
𝑥
≤ 00.03.265
𝑥
= Vulnerable software versions