QID 731364
Date Published: 2024-04-11
QID 731364: Telesquare TLR-2005KSH Router Remote Code Execution (RCE) Vulnerability
Telesquare Tlr-2005Ksh is a Sk Telecom Lte router from South Korea's Telesquare company.Telesquare TLR-2005Ksh versions 1.0.0 and 1.1.4 have an unauthorized remote command execution vulnerability. An attacker can exploit this vulnerability to execute system commands without authorization through the Cmd parameter and obtain server permissions.
Affected Versions:
Telesquare TLR-2005Ksh versions 1.0.0 and 1.1.4
QID Detection Logic:
This QID sends a crafted payload as an HTTP GET request to the '/cgi-bin/admin.cgi' endpoint and checks for code execution.
Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to execute arbitrary code, leading to complete system compromise.
Solution
Customers are advised to upgrade their routers to the latest available version. For more information regarding the vulnerability, please refer to the Exploit Writeup
Vendor References
CVEs related to QID 731364
Software Advisories
| Advisory ID | Software | Component | Link |
|---|