CVE-2023-32349

CVE-2023-32349

Versions 00.07.00 through 00.07.03.4 of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. An authenticated attacker could use an exposed UCI configuration utility to change these variables and enable malicious parameters in the dump utility, which could result in arbitrary code execution.

Source: CVE-2023-32349

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다