CVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code execution on the underlying system.
Configurations

No configuration.

History

26 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 20:16

Updated : 2026-06-29 14:16


NVD link : CVE-2026-32833

Mitre link : CVE-2026-32833

CVE.ORG link : CVE-2026-32833


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')