[0day-rubbish] Lantronix SGX5150 9.13.0.0R7 Authenticated FsBrowseClean command injection to root RCE (7.2)
Lantronix SGX5150 firmware has an authenticated command-injection flaw that can yield root code execution.
The 0day Rubbish Research Team disclosed an authenticated OS command injection (CWE-78) in Lantronix SGX5150 firmware 9.13.0.0R7, an IT/OT device server. The FsBrowseClean handler insufficiently filters a path parameter, allowing injected commands and root code execution. The issue is scored 7.2. No CVE or in-the-wild exploitation is mentioned.
- Affects Lantronix SGX5150 firmware 9.13.0.0R7, an IT/OT device server.
- Authenticated command injection exists in the FsBrowseClean handler.
- Successful injection can execute commands as root.
- Scored 7.2; no CVE or active exploitation is stated.
Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Lantronix SGX5150, firmware 9.13.0.0R7, an IT/OT device server. Type: authenticated OS command injection (CWE-78) in the FsBrowseClean AJAX handler (0x5eea0) of /bin/ltrx_evo. A per-character filter blocks & | but permits single quote, hash and newline. The path POST parameter is concatenated into /sbin/ltrx_usb_umount '%s'...
This source does not provide full text. Read it at seclists.org.