FAIL › dossier
Telerik
VENDOR· dossier confidence 20%
Telerik, a provider of UI components and development tools, has a history of critical and high-severity vulnerabilities, including remote code execution flaws, indicating a need for improved security practices. Their products have been exploited, highlighting a potential risk to DIB/CMMC organizations. Further investigation into their current security development lifecycle is warranted.
PROFILE
CategorySoftware Development ToolsWhat they doTelerik provides UI components and development tools for building web, mobile, and desktop applications. They offer a range of products including UI controls, reporting tools, and testing frameworks.
Websitehttps://www.telerik.com ↗
SECURITY POSTURE
Telerik has demonstrated a history of critical and high-severity vulnerabilities in their products, particularly related to file upload and remote code execution. Their security posture requires significant improvement, evidenced by multiple publicly disclosed vulnerabilities.
Notable failures
- Insecure direct object reference flaw allowing file uploads (CVE-2017-11357)
- Arbitrary file uploads or code execution (CVE-2017-11317)
- Potential remote code execution
- Arbitrary file uploads
Patterns: Remote code execution vulnerabilities; Insecure file upload handling
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-11 | CVE-2017-11317 | high | Telerik UI for ASP.NET AJAX allowed remote attackers to upload arbitrary files and execute code due to an unrestricted file upload vulnerability. |
| 2023-01-26 | CVE-2017-11357 | critical | Telerik UI for ASP.NET AJAX suffered an insecure direct object reference flaw allowing file uploads and potential remote code execution. |
DOSSIER SOURCES
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- CVE Vulnerability Database — Search & Browse All CVEs - Strix · www.strix.ai
- Latest Vulnerabilities - TheHackerWire · www.thehackerwire.com
Open questions: What is the current status of CVE-2017-11357 and CVE-2017-11317? · What security practices are in place to prevent similar vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:05:15.959659+00:00