CVE-2018-17533: Teltonika RUT900 Firmware

Medium severity, CVSS 6.1. EPSS: 2% chance of exploitation in the next 30 days.

Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.

Affected products

  • Teltonika RUT900 Firmware: before 00.05.01.1 (fixed in 00.05.01.1)
  • Teltonika RUT950 Firmware: before 00.05.01.1 (fixed in 00.05.01.1)
  • Teltonika RUT955 Firmware: before 00.05.01.1 (fixed in 00.05.01.1)

Published 2018-10-15. Last modified 2026-06-17.