Command Injection in Teltonika RutOS via API Services
Teltonika RutOS 00.07.06.21 is vulnerable to post-authentication command injection via the ipsec.lua and openvpn.lua modules, allowing arbitrary root command execution.
Teltonika RutOS version 00.07.06.21, primarily used in industrial RUT2XX and RUT9XX routers, contains multiple command injection vulnerabilities in its web management API. The vulnerabilities originate in the ipsec.lua and openvpn.lua service modules, which handle user-supplied input for the 'sid' parameter in API requests. These parameters are passed to the 'logread' system command via 'vuci.util.exec' without sufficient sanitization or the use of shell-quoting helpers.
Because the 'uhttpd' web server runs with root privileges and lacks a user-drop directive, an authenticated attacker can trigger this vulnerability to execute arbitrary shell commands as root. The command output is captured and reflected back to the attacker in the HTTP JSON response, facilitating easier data exfiltration and further post-exploitation activity. The vulnerability affects the MIPS-based architecture common to these devices and was confirmed via dynamic analysis in a QEMU MIPS user-mode environment.
Attack Chain
- Attacker obtains valid administrative credentials for the RutOS web management interface via password spraying or credential stuffing.
- Attacker logs into the web interface to obtain a valid JWT session token.
- Attacker constructs a malicious URL path segment for the /api/ipsec/status/ or /api/openvpn/status/ endpoint.
- The payload is crafted to include shell metacharacters such as single quotes and semicolons to escape the vulnerable 'logread' command arguments.
- Attacker sends an authenticated GET request containing the injected payload to the target API endpoint.
- The backend 'ipsec.lua' or 'openvpn.lua' service module unsafely concatenates the payload into a command executed by 'vuci.util.exec' (/bin/sh -c).
- The system executes the injected arbitrary commands with root privileges.
- The HTTP response body captures the command output within the JSON '.data.logs' field, providing immediate feedback to the attacker.
Impact
Successful exploitation allows an attacker to achieve full remote code execution with root privileges on the industrial router. This can lead to complete device compromise, network traffic interception, modification of firewall and routing rules, and the ability to pivot into the internal OT/IT network segments where the router is deployed.
Recommendation
- Audit web management logs for administrative access originating from unauthorized or unusual source IPs.
- Restrict access to the router's web management interface (uhttpd) to trusted internal management subnets.
- Change default administrative credentials immediately if not already performed.
- Monitor for HTTP POST/GET requests targeting /api/ipsec/status/ or /api/openvpn/status/ that contain suspicious shell metacharacters such as semicolons, single quotes, or common command syntax (e.g., 'id', 'cat').
Immediate actions
Restrict web management interface access to authorized IP ranges.
Threat Hunt
Search web logs for HTTP requests to /api/ipsec/status/ or /api/openvpn/status/ containing special characters.
Data: Web server access logs
Mitigations
Disable remote web management access if not required.
Teltonika RutOS 00.07.06.21