CVE-2023-32349: High severity teltonika remote management system (rms) vulnerability
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32349?
CVE-2023-32349 is a vulnerability in Teltonika’s RUT router firmware versions 00.07.03.4 and prior that allows an authenticated attacker to use an exposed UCI configuration file to execute arbitrary commands and potentially gain unauthorized access to the system.
What is the severity of CVE-2023-32349?
The severity of CVE-2023-32349 is high, with a CVSS score of 8.8.
How can an attacker exploit CVE-2023-32349?
An authenticated attacker can exploit CVE-2023-32349 by using the exposed UCI configuration file to execute arbitrary commands and gain unauthorized access to the system.
Which Teltonika router firmware versions are affected by CVE-2023-32349?
Teltonika’s RUT router firmware versions 00.07.03.4 and prior are affected by CVE-2023-32349.
Is Teltonika-networks Rut200 vulnerable to CVE-2023-32349?
No, Teltonika-networks Rut200 is not vulnerable to CVE-2023-32349.