An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-03-28T16:48:34
Updated: 2024-08-05T11:44:20.805Z
Reserved: 2018-12-05T00:00:00
Link: CVE-2018-19879
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-28T17:29:00.427
Modified: 2024-11-21T03:58:44.470
Link: CVE-2018-19879
Redhat
No data.