← Vulnerability feed

Vulnerability record · CVE-2021-45428 · published 3 January 2022

CVE-2021-45428: Telesquare TLR-2005KSH router allows arbitrary file upload via PUT

Telesquare · Tlr 2005ksh Firmware

TLR-2005KSH firmware is affected by an incorrect access control flaw: the HTTP PUT method is enabled, letting an attacker upload arbitrary files, including HTML and CGI. Because uploaded CGI can be executed, this is effectively remote code execution on the device. The record does not list specific affected firmware versions.

9.8 CVSS 3.1 Critical EPSS 57% · top 1.0% CWE-639 · Insecure direct object reference
9.8CVSS 3.1 base score, v2 7.5
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent exposure for any internet-facing TLR-2005KSH device.

What it is

TLR-2005KSH firmware is affected by an incorrect access control flaw: the HTTP PUT method is enabled, letting an attacker upload arbitrary files, including HTML and CGI. Because uploaded CGI can be executed, this is effectively remote code execution on the device. The record does not list specific affected firmware versions.

Impact

An unauthenticated attacker can place arbitrary files on the device and execute uploaded CGI, gaining code execution with the web server's privileges and full control over confidentiality, integrity and availability.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or LAN-exposed TLR-2005KSH management interface is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.56931 (99th percentile) and public references are tagged Exploit, indicating exploit code is publicly available and exploitation is likely.

What to do

  • Apply the vendor firmware update for TLR-2005KSH if one is available; the record does not name a fixed version, so confirm with Telesquare.
  • If no patch exists, disable the HTTP PUT method on the device or block it at a reverse proxy/WAF.
  • Remove the management interface from the public internet; restrict access to a trusted management VLAN or VPN.
  • Disable or restrict CGI execution on the device where the configuration allows it.
  • Replace end-of-life devices that cannot be patched or hardened.

Detection

  • Alert on HTTP PUT requests to the TLR-2005KSH web interface, especially with .html, .cgi or script-like extensions.
  • Monitor the device's web root and upload directories for newly created or modified files.
  • Watch for unexpected processes spawned by the device's web server or outbound connections from the device after uploads.
  • Review web server logs for PUT requests returning 200/201 from untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-45428 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-26010Telesquare tlr-2005ksh firmware improper access control vulnerabilityTelesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.EPSS 0.40%9.8CVE-2025-26011Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.EPSS 0.44%9.8CVE-2025-26005Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityTelesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.EPSS 0.44%9.8CVE-2025-26006Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.EPSS 0.44%9.8CVE-2025-26007Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.EPSS 0.44%9.8CVE-2025-26008Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityIn Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.EPSS 0.44%9.8CVE-2025-26002Telesquare tlr-2005ksh firmware classic buffer overflow vulnerabilityTelesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.EPSS 0.49%9.8CVE-2025-26003Telesquare tlr-2005ksh firmware code injection vulnerabilityTelesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2021-45428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.