HIGH · 8.0

CVE-2023-32350

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the v...

Vulnerability Description

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Teltonika-NetworksRut200 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut200-
Teltonika-NetworksRut240 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut240-
Teltonika-NetworksRut241 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut241-
Teltonika-NetworksRut300 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut300-
Teltonika-NetworksRut360 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut360-
Teltonika-NetworksRut901 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut901-
Teltonika-NetworksRut950 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut950-
Teltonika-NetworksRut951 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut951-
Teltonika-NetworksRut955 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut955-
Teltonika-NetworksRut956 Firmware>= 00.07.00, <= 00.07.03
Teltonika-NetworksRut956-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32350?

CVE-2023-32350 is a vulnerability with a CVSS score of 8.0 (HIGH). Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the v...

How severe is CVE-2023-32350?

CVE-2023-32350 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-32350?

Check the references section above for vendor advisories and patch information. Affected products include: Teltonika-Networks Rut200 Firmware, Teltonika-Networks Rut200, Teltonika-Networks Rut240 Firmware, Teltonika-Networks Rut240, Teltonika-Networks Rut241 Firmware.