PT-2026-52898 · Cudy · Lt300 3.0
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cudy LT300 3.0 versions prior to 2.5.12
Description
Authenticated attackers can execute arbitrary commands on the underlying system by injecting shell metacharacters into the
cbid.system.ntp.current POST parameter within the system time configuration interface. This issue allows for remote code execution via the NTP settings endpoint.Recommendations
Update Cudy LT300 3.0 to version 2.5.12 or later.
Avoid using the
cbid.system.ntp.current parameter in the NTP settings endpoint until the update is applied.Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lt300 3.0