logo

Triple Threat: Breaking Teltonika Routers Three Ways

ID: 92eafb07-975a-5cf6-9654-010d1c3072f8

STIX ID: report--92eafb07-975a-5cf6-9654-010d1c3072f8

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2023-10-17

Date Updated: 2026-04-17

Author: Noam Moshe; Roni Gavrilov-Otorio

...
...

Comprehensive research by Claroty Team82 and OTORIO discovered eight critical vulnerabilities in Teltonika Networks’ RMS and RUT industrial routers—ranging from unauthenticated device claiming and weak SN/MAC-based certificate issuance to tcpdump command-injection RCE, stored XSS for account takeover, and VPN-based SSRF into internal cloud services—enabling remote device takeover, cloud account compromise, and access to internal infrastructure across thousands of internet-exposed devices; fixes were coordinated with Teltonika and CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.