Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with all Teltonika devices connected to the VPN. The OpenVPN server also allows users to route through it. An attacker could route a connection to a remote server through the OpenVPN server, enabling them to scan and access data from other Teltonika devices connected to the VPN.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:NTeltonika Remote Management System
APPTeltonika< 4.10.0
Powiązane podatności
Nieautoryzowana rejestracja urządzeń w Teltonika RMS umożliwiająca RCE
Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerabil...
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed...
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to ...
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim t...