High severity8.0NVD Advisory· Published May 22, 2023· Updated Jun 17, 2026
CVE-2023-32350
CVE-2023-32350
Description
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- cpe:2.3:o:teltonika-networks:rut200_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut240_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut241_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut300_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut360_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut901_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
cpe:2.3:o:teltonika-networks:rut950_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:teltonika-networks:rut950_firmware:*:*:*:*:*:*:*:*range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut955_firmware:*:*:*:*:*:*:*:*range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut951_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rut956_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx08_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx09_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx10_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx11_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx12_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx14_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutx50_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- cpe:2.3:o:teltonika-networks:rutxr1_firmware:*:*:*:*:*:*:*:*Range: >=00.07.00,<=00.07.03
- Range: 00.07.00-00.07.03
- Teltonika/RUT model routersv5Range: 00.07.00
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-23-131-08nvdThird Party AdvisoryUS Government Resource
News mentions
1- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut TurbineThe Hacker News · Aug 11, 2026