Telesquare's vulnerability footprint centers on a narrow set of embedded networking devices, particularly its TLR-2005KSH router and related firmware, that are deployed in industrial, enterprise, and service-provider environments where uptime and remote management are critical. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the appeal of remotely accessible embedded systems to attackers and the memory-unsafe implementation typical of legacy firmware. The exposure recurs across buffer overflows, authorization bypass conditions, command injection, and information disclosure weaknesses that are characteristic of devices with weak input validation and limited access controls. Defenders should prioritize inventory and isolation of affected devices, particularly internet-reachable instances, and treat firmware updates as urgent when available. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telesquare over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46422CRITICAL Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. | Apr 27, 2022 | 9.8 | 90 | NO | YES |
CVE-2021-46419CRITICAL An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts. | Apr 7, 2022 | 9.1 | 83 | NO | YES |
CVE-2021-45428CRITICAL TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats. | Jan 3, 2022 | 9.8 | 80 | NO | YES |
CVE-2021-46424CRITICAL Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE requ | Apr 27, 2022 | 9.1 | 61 | NO | YES |
CVE-2021-46418HIGH An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts. | Apr 7, 2022 | 7.5 | 57 | NO | YES |
CVE-2024-29269HIGH An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter. | Apr 10, 2024 | 8.8 | 43 | NO | YES |
CVE-2025-9603CRITICAL A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation | Aug 29, 2025 | 9.8 | 37 | NO | NO |
CVE-2017-20223CRITICAL Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resou | Mar 16, 2026 | 9.8 | 31 | NO | NO |
CVE-2017-20224CRITICAL Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting en | Mar 16, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-26011CRITICAL Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword. | Mar 26, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telesquare.
Media articles that mention a CVE ID that affects a product developed by Telesquare — matched by CVE ID, not by vendor name.