[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)
Teltonika RutOS 00.07.06.21 has an authenticated ipsec.lua command injection that runs commands as root.
0day Rubbish disclosed an authenticated command injection (CWE-78) in Teltonika RutOS 00.07.06.21, in the ipsec.lua logread handler. An authenticated administrator can run commands as root, and command output is reflected in the JSON response. The issue is scored CVSS 8.8 (AV:N/AC:L/PR:L). The post includes a reproducible proof-of-concept and does not assign a CVE.
- Authenticated command injection in RutOS ipsec.lua logread
- An administrator can execute commands as root on the router
- Command output is reflected in the JSON response
- CVSS 8.8 on RutOS 00.07.06.21; a PoC was published
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Teltonika RutOS 00.07.06.21. Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact: root command execution on the router, with command output reflected into the JSON response Authentication: authenticated administrator Full technical analysis and a reproducible proof-of-concept:...
This source does not provide full text. Read it at seclists.org.