Teltonika Networks Remote Management System
cpe:2.3:a:teltonika:remote_management_system:*:*:*:*:*:*:*
- < 5.7
A vulnerability allowing account pre-hijacking has been identified in Teltonika Networks Remote Management System (RMS) versions prior to 5.7. This issue arises from a misuse of the invite functionality. When a victim receives a pending invite and registers directly on the platform, they are unknowingly added to the attacker's company. Consequently, the attacker gains the ability to manage the victim's account and company.
Exploitation of this vulnerability allows an attacker to take control of a victim's account and manage their associated company within the Teltonika RMS platform.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.