CVE-2025-9603

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:telesquare:tlr-2005ksh_firmware:1.2.4:*:*:*:*:*:*:*
cpe:2.3:h:telesquare:tlr-2005ksh:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-29 02:15

Updated : 2025-09-11 12:41


NVD link : CVE-2025-9603

Mitre link : CVE-2025-9603

CVE.ORG link : CVE-2025-9603


JSON object : View

Products Affected

telesquare

  • tlr-2005ksh
  • tlr-2005ksh_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')