Teltonika Networks develops industrial-grade cellular and networking devices for remote management and IoT applications, with a focused vulnerability profile concentrated across its router and gateway firmware lines such as the TRB245, RUT240, and RUT955. The vendor's disclosures span embedded networking and device-management firmware, where the attack surface centers on remote-access and configuration interfaces typical of field-deployed industrial equipment. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teltonika Networks over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32349HIGH
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validat | May 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2020-5770HIGH Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a c | Aug 3, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-5786HIGH Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a cr | Oct 1, 2020 | 8.8 | 25 | NO | NO |
CVE-2023-32350HIGH
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit | May 22, 2023 | 8.8 | 22 | NO | NO |
CVE-2020-5773HIGH Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations. | Aug 3, 2020 | 8.8 | 22 | NO | NO |
CVE-2023-31728HIGH Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even though the UI shows t | Feb 17, 2024 | 7.0 | 20 | NO | NO |
CVE-2020-5771HIGH Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive. | Aug 3, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-5772HIGH Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file. | Aug 3, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-5789MEDIUM Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk. | Oct 1, 2020 | 6.5 | 18 | NO | NO |
CVE-2020-5787MEDIUM Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove act | Oct 1, 2020 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teltonika Networks.
Media articles that mention a CVE ID that affects a product developed by Teltonika Networks — matched by CVE ID, not by vendor name.