Podatność CVE-2023-32349


Publikacja: 2023-05-22

Opis:

Versions 00.07.00 through 00.07.03.4 of Teltonika??s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.

Typ:

CWE-15

(External Control of System or Configuration Setting)

 Referencje:
https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-08

Copyright 2024, cxsecurity.com

 

Back to Top