# CVE-2023-2588

## Summary

- **CVE ID:** CVE-2023-2588
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-830
- **Published:** May 22, 2023
- **Last Modified:** Mar 13, 2026

## Description

Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web management services over the cloud proxy. A user can request a web proxy and obtain a URL in the Remote Management System cloud subdomain. This URL could be shared with others without Remote Management System authentication . An attacker could exploit this vulnerability to create a malicious webpage that uses a trusted and certified domain. An attacker could initiate a reverse shell when a victim connects to the malicious webpage, achieving remote code execution on the victim device.

## Affected Products

- Teltonika — Remote Management System (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.55%
- **EPSS Percentile:** 67.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._