cvedb.io
CVE-2017-8116
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2017-07-03T16:29:00.557 · Last modified 2026-06-17T01:25:47.943

Summary

The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.

Affected products

teltonika — rut900_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when teltonika ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.