Remote Code Execution in Baicells RTS Platform
CVE-2023-24508
8.1HIGH
What is CVE-2023-24508?
Baicells Nova LTE TDD eNodeB devices, including models 227, 233, 243, and 246, are susceptible to a remote shell code exploitation vulnerability. This issue arises from improper handling of HTTP command injections, allowing an unauthenticated attacker to execute system commands with root privileges. The exploitation pathway involves pre-login command execution, which has been validated by independent analysis. Users are strongly advised to upgrade to the latest firmware version to mitigate this security threat.
Affected Version(s)
Nova 227 RTS 0 <= 3.6.6
Nova 233 RTS 0 <= 3.6.6
Nova 246 RTS 0 <= 3.6.6
