Vulnerability Details CVE-2020-5769
Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.7%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-5769
-
cpe:2.3:h:teltonika-networks:gateway_trb245:-
-
cpe:2.3:o:teltonika-networks:gateway_trb245_firmware:trb2_r_00.02.02