Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been claimed, or whether the attempt to claim a device was successful. An attacker could exploit this to create a list of the serial numbers and MAC addresses of all devices cloud-connected to the Remote Management System.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NTeltonika Remote Management System
APPTeltonika< 4.10.0
Powiązane podatności
Nieautoryzowana rejestracja urządzeń w Teltonika RMS umożliwiająca RCE
Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerabil...
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed...
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to ...
Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub fea...