Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:34:23.944Z

Reserved: 2023-05-08T22:09:33.450Z

Link: CVE-2023-32349

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:24.909Z

cve-icon NVD

Status : Modified

Published: 2023-05-22T16:15:10.420

Modified: 2024-11-21T08:03:09.730

Link: CVE-2023-32349

cve-icon Redhat

No data.