Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 | Third Party Advisory US Government Resource |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
History
21 Nov 2024, 08:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - Third Party Advisory, US Government Resource | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
01 Jun 2023, 17:55
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08 - Third Party Advisory, US Government Resource | |
CPE | cpe:2.3:o:teltonika-networks:rutxr1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut956:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx09:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx08:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut300:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut901:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutxr1:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut901_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut951:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx10:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx14:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut955_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut360:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx09_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut955:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx50:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut241:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut240:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx11_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx12_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut240_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx11:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut200:-:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut950_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut360_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut951_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx14_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut241_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rutx08_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut956_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:teltonika-networks:rut300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rutx12:-:*:*:*:*:*:*:* cpe:2.3:h:teltonika-networks:rut950:-:*:*:*:*:*:*:* |
22 May 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-22 16:15
Updated : 2024-11-21 08:03
NVD link : CVE-2023-32350
Mitre link : CVE-2023-32350
CVE.ORG link : CVE-2023-32350
JSON object : View
Products Affected
teltonika-networks
- rut950
- rut241
- rutx12_firmware
- rut901
- rut950_firmware
- rut240
- rutx09
- rut955_firmware
- rut241_firmware
- rutx50
- rut360_firmware
- rutx09_firmware
- rutx11_firmware
- rutxr1_firmware
- rutx14_firmware
- rutx08
- rutxr1
- rutx14
- rut901_firmware
- rut956
- rut956_firmware
- rut300
- rut200_firmware
- rutx08_firmware
- rut200
- rut240_firmware
- rutx11
- rut300_firmware
- rutx10_firmware
- rut951_firmware
- rut360
- rut951
- rutx10
- rutx12
- rutx50_firmware
- rut955
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')