Cudy · Lt300 3.0 · CVE-2026-32833
**Name of the Vulnerable Software and Affected Versions**
Cudy LT300 3.0 versions prior to 2.5.12
**Description**
Authenticated attackers can execute arbitrary commands on the underlying system by injecting shell metacharacters into the `cbid.system.ntp.current` POST parameter within the system time configuration interface. This issue allows for remote code execution via the NTP settings endpoint.
**Recommendations**
Update Cudy LT300 3.0 to version 2.5.12 or later.
Avoid using the `cbid.system.ntp.current` parameter in the NTP settings endpoint until the update is applied.