Medium severity6.8NVD Advisory· Published Oct 15, 2018· Updated Jun 17, 2026
CVE-2018-17534
CVE-2018-17534
Description
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:teltonika:rut900_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:teltonika:rut900_firmware:*:*:*:*:*:*:*:*range: <00.04.233
- cpe:2.3:o:teltonika:rut950_firmware:*:*:*:*:*:*:*:*range: <00.04.233
- cpe:2.3:o:teltonika:rut955_firmware:*:*:*:*:*:*:*:*range: <00.04.233
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/149779/Teltonika-RUT9XX-Missing-Access-Control-To-UART-Root-Terminal.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Oct/28nvdExploitMailing ListThird Party Advisory
- github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180319-02_Teltonika_Incorrect_Access_ControlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.