Skip to content
COOEY

FAIL › dossier

Telerik

VENDOR

· dossier confidence 20%

Telerik, a provider of UI components and development tools, has a history of critical and high-severity vulnerabilities, including remote code execution flaws, indicating a need for improved security practices. Their products have been exploited, highlighting a potential risk to DIB/CMMC organizations. Further investigation into their current security development lifecycle is warranted.

PROFILE
CategorySoftware Development ToolsWhat they doTelerik provides UI components and development tools for building web, mobile, and desktop applications. They offer a range of products including UI controls, reporting tools, and testing frameworks. Websitehttps://www.telerik.com ↗
SECURITY POSTURE

Telerik has demonstrated a history of critical and high-severity vulnerabilities in their products, particularly related to file upload and remote code execution. Their security posture requires significant improvement, evidenced by multiple publicly disclosed vulnerabilities.

Notable failures
  • Insecure direct object reference flaw allowing file uploads (CVE-2017-11357)
  • Arbitrary file uploads or code execution (CVE-2017-11317)
  • Potential remote code execution
  • Arbitrary file uploads
Patterns: Remote code execution vulnerabilities; Insecure file upload handling
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-04-11 CVE-2017-11317 high Telerik UI for ASP.NET AJAX allowed remote attackers to upload arbitrary files and execute code due to an unrestricted file upload vulnerability.
2023-01-26 CVE-2017-11357 critical Telerik UI for ASP.NET AJAX suffered an insecure direct object reference flaw allowing file uploads and potential remote code execution.
Open questions: What is the current status of CVE-2017-11357 and CVE-2017-11317? · What security practices are in place to prevent similar vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:05:15.959659+00:00