vendor:
TLR-2855KS6
by:
Momen Eldawakhly
9.1
CVSS
CRITICAL
Arbitrary File Deletion
20
CWE
Product Name: TLR-2855KS6
Affected Version From: TLR-2855KS6
Affected Version To: TLR-2855KS6
Patch Exists: YES
Related CWE: CVE-2021-46419
CPE: h:telesquare:tlr-2855ks6
Platforms Tested: Linux [Firefox]
2022
Telesquare TLR-2855KS6 – Arbitrary File Deletion
An arbitrary file deletion vulnerability exists in Telesquare TLR-2855KS6. A remote attacker can send a specially crafted HTTP request to the vulnerable device to delete arbitrary files. This can be exploited to delete critical system files and cause a denial of service.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update their devices to the latest version.