VYPR

Tlr 2005ksh Firmware

by Telesquare

CVEs (17)

  • CVE-2021-45428CriJan 3, 2022
    risk 0.71cvss 9.8epss 0.57

    TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

  • CVE-2021-46424CriApr 27, 2022
    risk 0.65cvss 9.1epss 0.36

    Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

  • CVE-2025-26011CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.

  • CVE-2025-26010CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.

  • CVE-2025-26008CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.

  • CVE-2025-26007CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.

  • CVE-2025-26006CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.

  • CVE-2025-26005CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.

  • CVE-2025-26004CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.

  • CVE-2025-26003CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

  • CVE-2025-26002CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.

  • CVE-2024-29269HigApr 10, 2024
    risk 0.58cvss 8.8epss 0.06

    An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

  • CVE-2025-28361HigMar 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.

  • CVE-2025-26009HigMar 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

  • CVE-2025-26001HigMar 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.

  • CVE-2025-9603MedAug 29, 2025
    risk 0.42cvss 6.3epss 0.08

    A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to command injection. The attack may be performed from a remote…

  • CVE-2021-46423MedApr 27, 2022
    risk 0.35cvss 5.3epss 0.02

    Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file.