CVE-2026-32833
HIGHCudy LT300 3.0 OS Command Injection via NTP Configuration
Title source: cnaDescription
Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code execution on the underlying system.
References (2)
Core 2
Core References
Patch release-notes
patch
https://www.cudy.com/en-us/pages/download-center/lt300-3-0
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/cudy-lt300-os-command-injection-via-ntp-configuration
Scores
CVSS v3
8.8
EPSS
0.0134
EPSS Percentile
68.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
Shenzhen Cudy Technology Co., Ltd./LT300 3.0
< 2.5.12
Published
Jun 26, 2026
Tracked Since
Jun 27, 2026