CVE-2017-8116: Teltonika RUT900 Firmware
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.
Affected products
- Teltonika RUT900 Firmware: up to and including 00.03.265
- Teltonika RUT905 Firmware: up to and including 00.03.265
- Teltonika RUT950 Firmware: up to and including 00.03.265
- Teltonika RUT955 Firmware: up to and including 00.03.265
Published 2017-07-03. Last modified 2026-06-17.