Vulnerability Description
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teltonika-Networks | Rut200 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut200 | - |
| Teltonika-Networks | Rut240 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut240 | - |
| Teltonika-Networks | Rut241 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut241 | - |
| Teltonika-Networks | Rut300 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut300 | - |
| Teltonika-Networks | Rut360 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut360 | - |
| Teltonika-Networks | Rut901 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut901 | - |
| Teltonika-Networks | Rut950 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut950 | - |
| Teltonika-Networks | Rut951 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut951 | - |
| Teltonika-Networks | Rut955 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut955 | - |
| Teltonika-Networks | Rut956 Firmware | >= 00.07.00, <= 00.07.03 |
| Teltonika-Networks | Rut956 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-32350?
CVE-2023-32350 is a vulnerability with a CVSS score of 8.0 (HIGH). Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the v...
How severe is CVE-2023-32350?
CVE-2023-32350 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32350?
Check the references section above for vendor advisories and patch information. Affected products include: Teltonika-Networks Rut200 Firmware, Teltonika-Networks Rut200, Teltonika-Networks Rut240 Firmware, Teltonika-Networks Rut240, Teltonika-Networks Rut241 Firmware.