Junglewise Threat Intelligence

CVE-2026-32833: Cudy LT300 OS command injection in NTP configuration

CVE-2026-32833 · Severity: high · CVSS 8.8 · Published 2026-06-26

Vendors: Cudy.

Executive brief

A security vulnerability exists in the Cudy LT300 4G LTE router, a device used to provide internet connectivity. An authorized user can exploit a flaw in the system's time settings to take complete control of the device. This could allow an attacker to intercept network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Cudy LT300 3.0 router due to improper neutralization of shell metacharacters. The flaw is located in the 'cbid.system.ntp.current' POST parameter within the system time configuration interface. An authenticated attacker with network access to the management web interface can inject malicious payloads into this parameter to achieve remote code execution (RCE) with the privileges of the underlying system. The vulnerability is addressed in firmware version 2.5.12.

Affected products

  • Cudy LT300 3.0 prior to 2.5.12

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References