CVE-2023-31728 affects Teltonika RUT240 devices running firmware older than 07.04.2. When configured in bridge mode, the vulnerability causes SSH and HTTP services to be inadvertently exposed on the IPv6 WAN interface, despite UI settings indicating they should only be accessible via the LAN. This is a high-severity vulnerability (CVSS 7.0) with high impact on confidentiality, integrity, and availability, though it requires local privileges and high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 00.07.04.2CPE matchmatch criteria | cpe:2.3:o:teltonika-networks:rut240_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.