[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)
MultiTech Conduit AEP 6.3.6 has an authenticated filename injection that can yield root on IoT gateways.
0day Rubbish Research Team disclosed an authenticated OS command-injection flaw in MultiTech Conduit AEP 6.3.6, used on mtcdt, mtcdtip, and mtcdtiphp IoT gateways running mLinux. The admin-only import_config handler can be abused through an uploaded filename to gain root command execution (CWE-78). The management API is served on TCP port 8080. The issue is scored 7.2 and is not described as exploited in the wild.
47