CVE-2023-32350

HIGH

Teltonika RUT Router Firmware 00.07.00-00.07.03 - OS Command Injection via Lua Service Package Name

Title source: llm
STIX 2.1

Description

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08

Scores

CVSS v3 8.0
EPSS 0.0148
EPSS Percentile 70.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (18)
teltonika-networks/rut200_firmware 00.07.00 - 00.07.03
teltonika-networks/rut240_firmware 00.07.00 - 00.07.03
teltonika-networks/rut241_firmware 00.07.00 - 00.07.03
teltonika-networks/rut300_firmware 00.07.00 - 00.07.03
teltonika-networks/rut360_firmware 00.07.00 - 00.07.03
teltonika-networks/rut901_firmware 00.07.00 - 00.07.03
teltonika-networks/rut950_firmware 00.07.00 - 00.07.03
teltonika-networks/rut951_firmware 00.07.00 - 00.07.03
teltonika-networks/rut955_firmware 00.07.00 - 00.07.03
teltonika-networks/rut956_firmware 00.07.00 - 00.07.03
... and 8 more
Published May 22, 2023
Tracked Since Feb 18, 2026