OS Command Injection Vulnerability in Cudy LT300 3.0 by Cudy
CVE-2026-32833

8.7HIGH

What is CVE-2026-32833?

The Cudy LT300 3.0 device is vulnerable to OS command injection due to inadequate input validation in the system time configuration interface. Authenticated attackers can exploit this weakness by injecting shell metacharacters into the cbid.system.ntp.current POST parameter. This action allows for the execution of arbitrary commands on the underlying system, potentially leading to unauthorized access and control. It is crucial for users to upgrade to the latest firmware version (2.5.12 or higher) to mitigate this risk.

Affected Version(s)

LT300 3.0 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dan Owen
VulnCheck
.