Post

Teltonika RutOS Command Injection Vulnerability

Teltonika RutOS Command Injection Vulnerability

Teltonika RutOS Command Injection Vulnerability 🚨

A post-authentication command injection vulnerability has been identified in Teltonika RutOS, specifically affecting version 00.07.06.21. This vulnerability targets the RUT2XX / RUT200 industrial 4G/LTE router.

Key Details:

  • Affected Version: RutOS 00.07.06.21
  • CVSS Score: 8.8 (CWE-78, OS command injection, post-authentication)
  • Impact: Arbitrary command execution as root, with command stdout reflected in the response.

Vulnerability Description:

The injection occurs via GET /api/ipsec/status/<sid> with the Authorization: Bearer <JWT>. The character class excludes only ‘/’, allowing single quotes, semicolons, and spaces to survive. The ipsec.lua GET_TYPE_status function calls instances_status(self, self.sid) without an existence check, leading to command injection.

The command string is built as follows:

1
"logread -e '<" .. sid .. "-" .. sid .. "_c|'"

This allows for injected commands to run twice due to the concatenation of sid.

Verification:

The vulnerability was verified dynamically under QEMU MIPS user-mode emulation, demonstrating that the injected command can execute with root privileges.

Conclusion:

This vulnerability poses a significant risk, and it is crucial for users of affected devices to apply necessary mitigations.

For further details, you can read the complete article here: Read full article

This post is licensed under CC BY 4.0 by the author.