Teltonika RutOS Command Injection Vulnerability
Teltonika RutOS Command Injection Vulnerability 🚨
A post-authentication command injection vulnerability has been identified in Teltonika RutOS, specifically affecting version 00.07.06.21. This vulnerability targets the RUT2XX / RUT200 industrial 4G/LTE router.
Key Details:
- Affected Version: RutOS 00.07.06.21
- CVSS Score: 8.8 (CWE-78, OS command injection, post-authentication)
- Impact: Arbitrary command execution as root, with command stdout reflected in the response.
Vulnerability Description:
The injection occurs via GET /api/ipsec/status/<sid> with the Authorization: Bearer <JWT>. The character class excludes only ‘/’, allowing single quotes, semicolons, and spaces to survive. The ipsec.lua GET_TYPE_status function calls instances_status(self, self.sid) without an existence check, leading to command injection.
The command string is built as follows:
1
"logread -e '<" .. sid .. "-" .. sid .. "_c|'"
This allows for injected commands to run twice due to the concatenation of sid.
Verification:
The vulnerability was verified dynamically under QEMU MIPS user-mode emulation, demonstrating that the injected command can execute with root privileges.
Conclusion:
This vulnerability poses a significant risk, and it is crucial for users of affected devices to apply necessary mitigations.
For further details, you can read the complete article here: Read full article