CVE-2023-32350
HIGHTeltonika RUT Router Firmware 00.07.00-00.07.03 - OS Command Injection via Lua Service Package Name
Title source: llmDescription
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08
Scores
CVSS v3
8.0
EPSS
0.0148
EPSS Percentile
70.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (18)
teltonika-networks/rut200_firmware
00.07.00 - 00.07.03
teltonika-networks/rut240_firmware
00.07.00 - 00.07.03
teltonika-networks/rut241_firmware
00.07.00 - 00.07.03
teltonika-networks/rut300_firmware
00.07.00 - 00.07.03
teltonika-networks/rut360_firmware
00.07.00 - 00.07.03
teltonika-networks/rut901_firmware
00.07.00 - 00.07.03
teltonika-networks/rut950_firmware
00.07.00 - 00.07.03
teltonika-networks/rut951_firmware
00.07.00 - 00.07.03
teltonika-networks/rut955_firmware
00.07.00 - 00.07.03
teltonika-networks/rut956_firmware
00.07.00 - 00.07.03
... and 8 more
Published
May 22, 2023
Tracked Since
Feb 18, 2026