CVE-2026-32833: Cudy LT300 3.0 OS Command Injection via NTP Configuration
Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code execution on the underlying system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cudy LT300 firmwareto a version that resolves this vulnerability.Fixed in 2.5.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32833?
The severity of CVE-2026-32833 is rated high with a CVSS score of 8.8.
How do I fix CVE-2026-32833?
To fix CVE-2026-32833, update the Cudy LT300 firmware to version 2.5.12 or later.
What type of vulnerability is CVE-2026-32833?
CVE-2026-32833 is classified as an OS command injection vulnerability.
Who is affected by CVE-2026-32833?
Users running Cudy LT300 firmware versions prior to 2.5.12 are affected by CVE-2026-32833.
What can an attacker do with CVE-2026-32833?
An attacker can execute arbitrary commands on the device by injecting shell metacharacters into the NTP configuration parameters.