{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rutos-00.07.06.21/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RutOS (00.07.06.21)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","industrial-security"],"_cs_type":"advisory","_cs_vendors":["Teltonika"],"content_html":"\u003cp\u003eTeltonika RutOS version 00.07.06.21, primarily used in industrial RUT2XX and RUT9XX routers, contains multiple command injection vulnerabilities in its web management API. The vulnerabilities originate in the ipsec.lua and openvpn.lua service modules, which handle user-supplied input for the 'sid' parameter in API requests. These parameters are passed to the 'logread' system command via 'vuci.util.exec' without sufficient sanitization or the use of shell-quoting helpers.\u003c/p\u003e\n\u003cp\u003eBecause the 'uhttpd' web server runs with root privileges and lacks a user-drop directive, an authenticated attacker can trigger this vulnerability to execute arbitrary shell commands as root. The command output is captured and reflected back to the attacker in the HTTP JSON response, facilitating easier data exfiltration and further post-exploitation activity. The vulnerability affects the MIPS-based architecture common to these devices and was confirmed via dynamic analysis in a QEMU MIPS user-mode environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid administrative credentials for the RutOS web management interface via password spraying or credential stuffing.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the web interface to obtain a valid JWT session token.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious URL path segment for the /api/ipsec/status/ or /api/openvpn/status/ endpoint.\u003c/li\u003e\n\u003cli\u003eThe payload is crafted to include shell metacharacters such as single quotes and semicolons to escape the vulnerable 'logread' command arguments.\u003c/li\u003e\n\u003cli\u003eAttacker sends an authenticated GET request containing the injected payload to the target API endpoint.\u003c/li\u003e\n\u003cli\u003eThe backend 'ipsec.lua' or 'openvpn.lua' service module unsafely concatenates the payload into a command executed by 'vuci.util.exec' (/bin/sh -c).\u003c/li\u003e\n\u003cli\u003eThe system executes the injected arbitrary commands with root privileges.\u003c/li\u003e\n\u003cli\u003eThe HTTP response body captures the command output within the JSON '.data.logs' field, providing immediate feedback to the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to achieve full remote code execution with root privileges on the industrial router. This can lead to complete device compromise, network traffic interception, modification of firewall and routing rules, and the ability to pivot into the internal OT/IT network segments where the router is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit web management logs for administrative access originating from unauthorized or unusual source IPs.\u003c/li\u003e\n\u003cli\u003eRestrict access to the router's web management interface (uhttpd) to trusted internal management subnets.\u003c/li\u003e\n\u003cli\u003eChange default administrative credentials immediately if not already performed.\u003c/li\u003e\n\u003cli\u003eMonitor for HTTP POST/GET requests targeting /api/ipsec/status/ or /api/openvpn/status/ that contain suspicious shell metacharacters such as semicolons, single quotes, or common command syntax (e.g., 'id', 'cat').\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T15:12:14Z","date_published":"2026-10-01T15:12:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-teltonika-rutos-rce/","summary":"Teltonika RutOS 00.07.06.21 is vulnerable to post-authentication command injection via the ipsec.lua and openvpn.lua modules, allowing arbitrary root command execution.","title":"Command Injection in Teltonika RutOS via API Services","url":"https://feed.craftedsignal.io/briefs/2026-10-teltonika-rutos-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - RutOS (00.07.06.21)","version":"https://jsonfeed.org/version/1.1"}