CVE-2023-35830

CRITICAL

STW TCG-4 and TCG-4lite Firmware - Unauthenticated Remote Code Execution via SMS

Title source: llm
STIX 2.1

Description

STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an attacker arbitrary remote code execution over LTE / 4G network via SMS.

Scores

CVSS v3 9.8
EPSS 0.0109
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (5)
stw-mobile-machines/tcg-4_firmware 3.01r1
stw-mobile-machines/tcg-4_firmware 3.02r0
stw-mobile-machines/tcg-4_firmware 3.03r0
stw-mobile-machines/tcg-4_firmware 3.04r2
stw-mobile-machines/tcg-4lite_firmware 3.04r2
Published Jun 29, 2023
Tracked Since Feb 18, 2026