Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

Project Subscriptions

Vendors Products
Teltonika-networks Subscribe
Rut200 Firmware Subscribe
Rut240 Firmware Subscribe
Rut241 Firmware Subscribe
Rut300 Firmware Subscribe
Rut360 Firmware Subscribe
Rut901 Firmware Subscribe
Rut950 Firmware Subscribe
Rut951 Firmware Subscribe
Rut955 Firmware Subscribe
Rut956 Firmware Subscribe
Rutx08 Firmware Subscribe
Rutx09 Firmware Subscribe
Rutx10 Firmware Subscribe
Rutx11 Firmware Subscribe
Rutx12 Firmware Subscribe
Rutx14 Firmware Subscribe
Rutx50 Firmware Subscribe
Rutxr1 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-36594 Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 17 Jan 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:34:13.864Z

Reserved: 2023-05-08T22:09:33.450Z

Link: CVE-2023-32350

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:24.899Z

cve-icon NVD

Status : Modified

Published: 2023-05-22T16:15:10.497

Modified: 2024-11-21T08:03:09.873

Link: CVE-2023-32350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses