CVE-2020-5769 describes a persistent cross-site scripting (XSS) vulnerability in Teltonika TRB2_R_00.02.02 firmware affecting Teltonika Networks TRB245 gateways. An authenticated attacker can inject malicious client-side code into the "DATA TO SERVER" configuration, leading to a medium severity CVSS score of 5.4. While the attack requires user interaction (UI:R) and authentication (PR:L), successful exploitation could result in limited confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
trb2_r_00.02.02CPE matchmatch criteria | cpe:2.3:o:teltonika-networks:gateway_trb245_firmware:trb2_r_00.02.02:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020Teltonika Gateway TRB245 Stored Cross-site Scripting
Jul 16, 2020