CVE-2023-32350: OS Command Injection
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32350?
CVE-2023-32350 is a command injection vulnerability in Teltonika’s RUT router firmware.
How does CVE-2023-32350 impact Teltonika's RUT router firmware?
CVE-2023-32350 allows an attacker to execute arbitrary commands on the affected router firmware.
Which versions of Teltonika's RUT router firmware are affected by CVE-2023-32350?
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware are affected by CVE-2023-32350.
What is the severity of CVE-2023-32350?
The severity of CVE-2023-32350 is high, with a CVSS score of 8.8.
How can I fix CVE-2023-32350 in Teltonika's RUT router firmware?
To fix CVE-2023-32350, it is recommended to update your Teltonika RUT router firmware to a version higher than 00.07.03.