Telesquare TLR-2005KSH Command Injection Vulnerability in internet.cgi

Vulnerability

A command injection vulnerability has been identified in the Telesquare TLR-2005KSH router, specifically in version 1.2.4. The issue arises within the CGI file 'internet.cgi', when the 'Command' parameter is set to 'lanCfg'. The vulnerability allows remote attackers to manipulate the 'Hostname' argument, leading to unauthorized command execution on the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected router.

Reproduction

To reproduce this vulnerability, send a request to '/cgi-bin/internet.cgi' with the 'Command' parameter set to 'lanCfg' and the 'hostname' parameter injected with a command payload, such as '$(cmd)'.

Added: Aug 29, 2025, 2:18 AM
Updated: Aug 29, 2025, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.