CVE-2023-32349: High severity teltonika remote management system (rms) vulnerability

Published May 22, 2023
·
Updated

Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.

Affected Software

40 affected components
Teltonika Remote Management System (RMS): Versions prior to 4.10.0 (affected by CVE-2023-32346, CVE-2023-32347, CVE-2023-32348, CVE-2023-2587, CVE-2023-2588)
Teltonika Remote Management System (RMS): Versions prior to 4.14.0 (affected by CVE-2023-2586)
Teltonika RUT model routers: Version 00.07.00 through 00.07.03.4 (affected by CVE-2023-32349)
Teltonika RUT model routers: Version 00.07.00 through 00.07.03 (affected by CVE-2023-32350)
Teltonika-networks Rut200 Firmware<=00.07.03.4
Teltonika-networks Rut200
Teltonika-networks Rut240 Firmware<=00.07.03.4
Teltonika-networks Rut240
Teltonika-networks Rut241 Firmware<=00.07.03.4
Teltonika-networks Rut241
Teltonika-networks Rut300 Firmware<=00.07.03.4
Teltonika-networks Rut300
Teltonika-networks Rut360 Firmware<=00.07.03.4
Teltonika-networks Rut360
Teltonika-networks Rut901 Firmware<=00.07.03.4
Teltonika-networks Rut901
Teltonika-networks Rut950 Firmware<=00.07.03.4
Teltonika-networks Rut950
Teltonika-networks Rut951 Firmware<=00.07.03.4
Teltonika-networks Rut951
Teltonika-networks Rut955 Firmware<=00.07.03.4
Teltonika-networks Rut955
Teltonika-networks Rut956 Firmware<=00.07.03.4
Teltonika-networks Rut956
Teltonika-networks Rutx08 Firmware<=00.07.03.4
Teltonika-networks Rutx08
Teltonika-networks Rutx09 Firmware<=00.07.03.4
Teltonika-networks Rutx09
Teltonika-networks Rutx10 Firmware<=00.07.03.4
Teltonika-networks Rutx10
Teltonika-networks Rutx11 Firmware<=00.07.03.4
Teltonika-networks Rutx11
Teltonika-networks Rutx12 Firmware<=00.07.03.4
Teltonika-networks Rutx12
Teltonika-networks Rutx14 Firmware>=00.07.00<=00.07.03.4
Teltonika-networks Rutx14
Teltonika-networks Rutx50 Firmware>=00.07.00<=00.07.03.4
Teltonika-networks Rutx50
Teltonika-networks Rutxr1 Firmware>=00.07.00<=00.07.03.4
Teltonika-networks Rutxr1

Event History

May 22, 2023
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-32349?

CVE-2023-32349 is a vulnerability in Teltonika’s RUT router firmware versions 00.07.03.4 and prior that allows an authenticated attacker to use an exposed UCI configuration file to execute arbitrary commands and potentially gain unauthorized access to the system.

2

What is the severity of CVE-2023-32349?

The severity of CVE-2023-32349 is high, with a CVSS score of 8.8.

3

How can an attacker exploit CVE-2023-32349?

An authenticated attacker can exploit CVE-2023-32349 by using the exposed UCI configuration file to execute arbitrary commands and gain unauthorized access to the system.

4

Which Teltonika router firmware versions are affected by CVE-2023-32349?

Teltonika’s RUT router firmware versions 00.07.03.4 and prior are affected by CVE-2023-32349.

5

Is Teltonika-networks Rut200 vulnerable to CVE-2023-32349?

No, Teltonika-networks Rut200 is not vulnerable to CVE-2023-32349.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203