vendor:
TLR-2855KS6
by:
Momen Eldawakhly (Cyber Guy)
7.5
CVSS
HIGH
Arbitrary File Creation
264
CWE
Product Name: TLR-2855KS6
Affected Version From: TLR-2855KS6
Affected Version To: TLR-2855KS6
Patch Exists: YES
Related CWE: CVE-2021-46418
CPE: h:telesquare:tlr-2855ks6
Platforms Tested: Linux [Firefox]
2022
Telesquare TLR-2855KS6 – Arbitrary File Creation
An arbitrary file creation vulnerability exists in Telesquare TLR-2855KS6. An attacker can send a specially crafted HTTP request to the vulnerable device to create a file with arbitrary content. This could allow an attacker to gain access to the device and execute malicious code.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their devices to the latest version.