[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)
MultiTech Conduit AEP 6.3.6 has an authenticated filename injection that can yield root on IoT gateways.
0day Rubbish Research Team disclosed an authenticated OS command-injection flaw in MultiTech Conduit AEP 6.3.6, used on mtcdt, mtcdtip, and mtcdtiphp IoT gateways running mLinux. The admin-only import_config handler can be abused through an uploaded filename to gain root command execution (CWE-78). The management API is served on TCP port 8080. The issue is scored 7.2 and is not described as exploited in the wild.
- Affects Conduit AEP 6.3.6 on models mtcdt, mtcdtip, and mtcdtiphp.
- Authenticated admin import_config filename injection yields root execution.
- Rated 7.2 (CWE-78); management API listens on TCP port 8080.
Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech Conduit AEP (models mtcdt / mtcdtip / mtcdtiphp), IoT gateways running mLinux on ARM 32-bit. Type: authenticated OS command injection (CWE-78) through the uploaded filename of the admin-only upload_config command. The management API is served by lighttpd on TCP 8080 and proxied to the proprietary FastCGI daemon /usr/bin/rcell_api. The import_config handler wraps the...
This source does not provide full text. Read it at seclists.org.