Vulnerability record · CVE-2021-46419 · published 7 April 2022
CVE-2021-46419: Telesquare TLR-2855KS6 router allows unauthenticated file deletion via DELETE
Telesquare · Tlr 2855ks6 Firmware
The Telesquare TLR-2855KS6 firmware exposes an endpoint that accepts HTTP DELETE requests without authentication, allowing arbitrary deletion of system files and scripts. Because the flaw is reachable over the network with no credentials or user interaction, it can render the device unusable or remove security-relevant components.
Description
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 with no authentication or user interaction and public exploit references plus very high EPSS make this an urgent exposure for any internet- or network-reachable TLR-2855KS6.
What it is
The Telesquare TLR-2855KS6 firmware exposes an endpoint that accepts HTTP DELETE requests without authentication, allowing arbitrary deletion of system files and scripts. Because the flaw is reachable over the network with no credentials or user interaction, it can render the device unusable or remove security-relevant components.
Impact
An attacker can delete system files and scripts on the device, causing denial of service, loss of configuration or functionality, and potentially weakening the device for follow-on attacks.
Attack surface
Reachable over the network via HTTP DELETE requests to the affected device; the CVSS vector shows no privileges required and no user interaction, so any host that can reach the management interface can trigger it.
Exploitation
Public exploit references are tagged Exploit, and EPSS is 0.71384 (99.38th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the vendor firmware update for TLR-2855KS6 if available; if no patch exists, isolate or replace the device.
- Restrict management access to a trusted network segment and block untrusted HTTP access to the device.
- Disable or firewall the affected HTTP DELETE functionality until a fix is deployed.
- Monitor vendor advisories for updated firmware and re-check exposure after patching.
Detection
- Alert on HTTP DELETE requests to the TLR-2855KS6 management interface from unexpected sources.
- Monitor device logs and file integrity for unexpected deletion of system files or scripts.
- Watch for sudden device unavailability or configuration loss consistent with file deletion.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166675/Telesquare-TLR-2855KS6-Arbitrary-File-Deletion.html | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/drive/folders/1TWw3Oy0wZImSHK_hj-tKkbn9sFgqqySp | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166675/Telesquare-TLR-2855KS6-Arbitrary-File-Deletion.html | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/drive/folders/1TWw3Oy0wZImSHK_hj-tKkbn9sFgqqySp | ExploitThird Party Advisory |
Track CVE-2021-46419 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-46419), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.