8.8

CVE-2023-32350

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teltonika-networksRut200 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut200 Version-
Teltonika-networksRut240 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut240 Version-
Teltonika-networksRut241 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut241 Version-
Teltonika-networksRut300 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut300 Version-
Teltonika-networksRut360 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut360 Version-
Teltonika-networksRut901 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut901 Version-
Teltonika-networksRut950 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut950 Version-
Teltonika-networksRut951 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut951 Version-
Teltonika-networksRut955 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut955 Version-
Teltonika-networksRut956 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRut956 Version-
Teltonika-networksRutx08 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx08 Version-
Teltonika-networksRutx09 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx09 Version-
Teltonika-networksRutx10 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx10 Version-
Teltonika-networksRutx11 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx11 Version-
Teltonika-networksRutx12 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx12 Version-
Teltonika-networksRutx14 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx14 Version-
Teltonika-networksRutx50 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutx50 Version-
Teltonika-networksRutxr1 Firmware Version >= 00.07.00 <= 00.07.03
   Teltonika-networksRutxr1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.523
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ics-cert@hq.dhs.gov 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.