CVE-2026-32833: Verified Repro With Script Download
CVE-2026-32833: Cudy LT300 3.0 OS command injection
CVE-2026-32833 is verified against Cudy LT300 V3 firmware · firmware. Affected versions: All firmware versions prior to 2.5.12 (confirmed vulnerable: 2.4.1, 2.4.5). Fixed in 2.5.12 (released 20-May-2026). Vulnerability class: Command Injection. This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00258.
What Is CVE-2026-32833?
CVE-2026-32833 is a high-severity OS command injection vulnerability in the Cudy LT300 3.0 router's LuCI web administration interface. Pruva reproduced it (reproduction REPRO-2026-00258).
CVE-2026-32833 Severity & CVSS Score
CVE-2026-32833 is rated high severity, with a CVSS base score of 8.8 out of 10.
High — serious impact or readily exploitable. Prioritize remediation.
Affected Cudy LT300 V3 firmware Versions
Cudy LT300 V3 firmware · firmware versions All firmware versions prior to 2.5.12 (confirmed vulnerable: 2.4.1, 2.4.5) are affected.
How to Reproduce CVE-2026-32833
pruva-verify REPRO-2026-00258 curl -O https://pruva.dev/api/v1/reproductions/REPRO-2026-00258/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Proof of Reproduction for CVE-2026-32833
- reached the target end-to-end
- full exploit chain demonstrated
- on the real production code path
- high confidence
- the upstream fix blocks the same trigger
HTTP form field cbid.system.ntp.current submitted to /cgi-bin/luci/admin/system/systime
- uhttpd
- /www/cgi-bin/luci
- luci.dispatcher/CBI
- model/cbi/system/systime.lua
- date -s '%s' fork_exec
Alternate vulnerable-version trigger via authenticated LuCI JSON-RPC /cgi-bin/luci/rpc/app method system.setclock reaching luci.apprpc.system.lua date -s shell sink; fixed 2.5.12 blocks the payload, so this is not a fixed-version bypass.
How the agent worked
Root Cause and Exploit Chain for CVE-2026-32833
- Affected versions: firmware before 2.5.12; reproduced against
LT300V3-R100-2.4.5-20250519-131314. - Fixed/control version:
LT300V3-R100-2.5.12-20260518-234632. - Risk level and consequences: high. An attacker with access to the administrative interface/session can execute shell commands in the router firmware context by submitting crafted time-setting form data. On a physical router this can lead to device compromise, persistence, traffic interception, or pivoting from the router.
Impact Parity
- Disclosed/claimed maximum impact: code execution / OS command injection via a router administrative interface API endpoint.
- Reproduced impact from this run: code execution. The reproduction created attacker-chosen proof files with controlled contents by sending HTTP POST requests to the original firmware
/cgi-bin/luci/admin/system/systimeendpoint through the firmwareuhttpdserver and original/www/cgi-bin/luciLuCI dispatcher/CBI path. - Parity:
full. - Not demonstrated: no post-exploitation persistence or interactive shell was attempted; the proof stops after deterministic command execution side effects.
Root Cause
The root cause is unsafe construction of a shell command from HTTP form input in the LuCI system time handler. In the vulnerable 2.4.5 firmware, the system time page includes bytecode string markers showing the affected flow: timeclock, date -s '%s', and fork_exec. When the CBI form is submitted with the manual time-setting option, the user-supplied cbid.system.ntp.current/time value is used in a date -s '<user value>' command. Because the value is surrounded by single quotes but not sanitized before shell execution, an attacker can close the quote and append a shell command, e.g. 2025-01-01 12:00:00'; echo MARKER > /tmp/proof; #.
The fixed 2.5.12 firmware preserves the same endpoint and command structure but adds a gsub sanitization marker in the same systime.lua handler before fork_exec. The fixed negative-control runs reached the same product endpoint and form handler but did not create the attacker-controlled proof files.
No public fix commit was provided in the ticket. The reproduction compares vendor firmware images directly: vulnerable LT300V3-R100-2.4.5-20250519-131314 versus fixed LT300V3-R100-2.5.12-20260518-234632.
Reproduction Steps
- Use
bundle/repro/reproduction_steps.sh. - The script:
- Downloads or reuses the vendor LT300 V3 2.4.5 and 2.5.12 firmware zip files.
- Extracts their SquashFS root filesystems.
- Runs the firmware
usr/sbin/uhttpdunderqemu-mipselandproot. - Uses the original firmware
/www/cgi-bin/luci,luci.dispatcher,luci.cbi, andusr/lib/lua/luci/model/cbi/system/systime.luapath for the endpoint. - Adds only emulation shims for router-only services/hardware state (
ubussession,bdinfo, and route-forbidden state) so the firmware web interface can run outside physical hardware; it does not replace the vulnerable endpoint handler. - Sends two vulnerable HTTP POST attempts to
/cgi-bin/luci/admin/system/systimewith payloads incbid.system.ntp.current. - Sends two equivalent fixed-version negative-control attempts through the same endpoint.
- Expected evidence:
- Vulnerable attempts create proof files containing
VULN_ATTEMPT_1_COMMAND_EXECUTEDandVULN_ATTEMPT_2_COMMAND_EXECUTED. - Fixed attempts do not create proof files.
- GET requests for both versions render the original
System TimeCBI form and includecbid.system.ntp.current, proving endpoint reachability.
- Vulnerable attempts create proof files containing
Evidence
Primary runtime evidence:
bundle/logs/reproduction_steps.logrecords successful runs.bundle/repro/runtime_manifest.jsonrecords the runtime endpoint path,service_started=true,healthcheck_passed=true, andtarget_path_reached=true.bundle/logs/artifacts/product/proof_summary.txtcontains:vuln attempt 1 proof: VULN_ATTEMPT_1_COMMAND_EXECUTEDvuln attempt 2 proof: VULN_ATTEMPT_2_COMMAND_EXECUTEDfixed attempt 1 no proof file (negative control passed)fixed attempt 2 no proof file (negative control passed)
bundle/logs/artifacts/http/vuln_attempt1_request.txtandbundle/logs/artifacts/http/vuln_attempt2_request.txtcontain the malicious POST fields sent to/cgi-bin/luci/admin/system/systime.bundle/logs/artifacts/http/vuln_attempt1_response_headers.txtshowsHTTP/1.1 200 OKandX-CBI-State: 1for a submitted form.bundle/logs/artifacts/http/fixed_attempt1_response_headers.txtshows the fixed endpoint was reached but did not accept the injected payload as a successful proof-producing command.bundle/logs/code_comparison.txtandbundle/logs/artifacts/product/code_identity.txtcapture firmware code identity and string-level handler differences. The vulnerable handler showstimeclock,date -s '%s', andfork_exec; the fixed handler additionally showsgsub.
Environment details:
- Firmware rootfs execution used
qemu-mipselandprootin user-mode emulation. - The production-facing server was the firmware
uhttpdbinary serving the original firmware web root. - The entrypoint was the HTTP endpoint
/cgi-bin/luci/admin/system/systime.
Recommendations / Next Steps
- Upgrade Cudy LT300 3.0 devices to firmware 2.5.12 or newer.
- Do not build shell commands by concatenating or formatting raw HTTP form values. Use argument-vector APIs where possible, or strictly validate time values against a narrow date/time grammar before invoking any command.
- If shell invocation is unavoidable, reject metacharacters such as quotes, semicolons, backticks, pipes, ampersands, redirection operators,
$(), and newlines, and add regression tests for command-injection payloads. - Add endpoint-level tests for
/cgi-bin/luci/admin/system/systimeverifying that invalid time values fail closed and cannot create shell side effects.
Additional Notes
- Idempotency confirmation:
bundle/repro/reproduction_steps.shwas run successfully multiple times consecutively after fixing non-root SquashFS extraction handling. Each run recreated fresh proof artifacts and revalidated both vulnerable and fixed firmware behavior. - The run uses emulation shims for hardware/session dependencies that are normally present on a physical router. The vulnerability proof itself is not a reimplemented handler: the HTTP request traverses firmware
uhttpd, original/www/cgi-bin/luci, LuCI dispatcher/CBI, and the original firmwaresystime.luabytecode handler. - The fixed-version negative control uses the actual fixed firmware handler rather than a hand-written surrogate.
Variant Analysis & Alternative Triggers for CVE-2026-32833
Fix Coverage / Assumptions
- The original fix appears to rely on removing the ability for a user-controlled time string to break out of the single-quoted
date -s '%s'shell argument. - The fixed 2.5.12 firmware explicitly covers:
usr/lib/lua/luci/model/cbi/system/systime.lua, the original/cgi-bin/luci/admin/system/systimeCBI form path. String markers showdate -s '%s',gsub, andfork_execin the fixed handler.usr/lib/lua/luci/apprpc/system.lua, the JSON-RPC application API path. String markers showdate -s '%s',gsub, andfork_execin the fixed handler.
- The fixed RPC endpoint returned an application-level error for the malicious parameter:
Invalid Parameter, and no proof file was created. - No
SECURITY.mdor detailed threat-model file was present inside the firmware rootfs. Cudy has a public “Report Vulnerability” page, but the extracted page did not publish exclusions that would make authenticated administrative command injection out of scope. The tested path crosses the same network administrative trust boundary as the parent issue, not a local-file or self-attack boundary. - The fix does not remove shell use entirely; it still leaves shell-command construction (
date -s '%s') present. However, the tested quote-breakout data path is covered in both observed time-setting handlers in 2.5.12.
Variant / Alternate Trigger
The confirmed alternate path is the LuCI JSON-RPC application endpoint rather than the CBI HTML form endpoint:
- Parent entrypoint:
POST /cgi-bin/luci/admin/system/systime, form fieldcbid.system.ntp.current, CBI modelusr/lib/lua/luci/model/cbi/system/systime.lua. - Variant entrypoint:
POST /cgi-bin/luci/rpc/app, JSON-RPC methodsystem.setclock, JSONparams[0], application RPC moduleusr/lib/lua/luci/apprpc/system.lua. - Sink:
luci.sys.call()invokingdate -s '%s'with the attacker-controlled time string in vulnerable firmware.
The variant reproducer sends JSON like:
{"jsonrpc":"2.0","id":1,"method":"system.setclock","params":["2025-01-01 12:00:00'; echo VULN_RPC_SETCLOCK_VARIANT_EXECUTED > /root/vuln_rpc_variant_proof; #"]}
On firmware 2.4.5 this creates /root/vuln_rpc_variant_proof in the emulated firmware root. On firmware 2.5.12 the same request does not create /root/fixed_rpc_variant_proof.
- Affected version tested:
LT300V3-R100-2.4.5-20250519-131314. - Fixed/control version tested:
LT300V3-R100-2.5.12-20260518-234632. - Risk level and consequences: high for affected firmware. An authenticated attacker with access to the router administrative web/RPC interface can execute shell commands in the router firmware context via JSON-RPC, leading to device compromise, persistence opportunities, traffic interception, or lateral movement from the router.
Impact Parity
- Disclosed/claimed maximum impact for the parent: OS command injection / code execution through the router administrative interface.
- Reproduced impact from this variant run: command execution through a different HTTP entrypoint. The vulnerable 2.4.5 run created
VULN_RPC_SETCLOCK_VARIANT_EXECUTEDvia JSON-RPC. - Parity:
fullfor the vulnerable-version alternate trigger;nonefor bypass against fixed 2.5.12. - Not demonstrated: persistence, interactive shell, unauthenticated access, and post-exploitation actions were not attempted. The fixed firmware did not execute the payload.
Root Cause
The same underlying bug class is reachable from a second LuCI time-setting surface in the vulnerable firmware. In usr/lib/lua/luci/apprpc/system.lua, the exported setclock function accepts a time string from JSON-RPC and passes it to a shell command template containing date -s '%s'. Because vulnerable 2.4.5 does not sanitize a single quote in that string, the input closes the shell quote and appends an attacker command. The fixed 2.5.12 firmware keeps the command template but adds quote handling/validation (gsub marker and runtime Invalid Parameter response), preventing the tested breakout. No public source-code fix commit was supplied; analysis compares vendor firmware images directly.
Reproduction Steps
- Run
bundle/vuln_variant/reproduction_steps.sh. - The script:
- Acquires or reuses vendor LT300 V3 firmware images for 2.4.5 and 2.5.12.
- Extracts their SquashFS root filesystems.
- Runs the original firmware
uhttpdand LuCI RPC stack underqemu-mipsel/proot. - Adds only emulation shims for router-only session/hardware dependencies.
- Sends the same JSON-RPC
system.setclockcommand-injection payload to vulnerable and fixed firmware.
- Expected evidence:
- Vulnerable 2.4.5 creates
vuln_rpc_variant_proofcontainingVULN_RPC_SETCLOCK_VARIANT_EXECUTED. - Fixed 2.5.12 does not create
fixed_rpc_variant_proofand returns an invalid-parameter style response. - The script exits
1because this is an alternate trigger on the vulnerable version, not a fixed-version bypass.
- Vulnerable 2.4.5 creates
Evidence
Primary evidence files:
bundle/logs/vuln_variant/reproduction_steps.logrecords the successful side-by-side test.bundle/logs/vuln_variant/product/proof_summary.txtcontains:vuln proof: VULN_RPC_SETCLOCK_VARIANT_EXECUTEDfixed no proof file (negative control passed)
bundle/logs/vuln_variant/http/vuln_rpc_request.jsoncontains the malicious JSON-RPC request to/cgi-bin/luci/rpc/app.bundle/logs/vuln_variant/http/vuln_rpc_response_body.txtshows a JSON-RPC response withresult:nullfrom the vulnerable target.bundle/logs/vuln_variant/http/fixed_rpc_response_body.txtshows the fixed target returnedInvalid Parameterfor the same payload.bundle/logs/vuln_variant/product/code_identity.txtrecords firmware versions and hashes foruhttpd,/www/cgi-bin/luci,luci/controller/rpc.lua,luci/app.lua,luci/apprpc/system.lua, andmodel/cbi/system/systime.lua.bundle/vuln_variant/runtime_manifest.jsonrecords the runtime endpoint and tested versions.
Environment details:
- Runtime used Cudy firmware rootfs, firmware
uhttpd, LuCI JSON-RPC dispatcher,qemu-mipsel, andproot. - Firmware versions came from
/etc/rom_version: vulnerable2.4.5-20250519-131314, fixed2.5.12-20260518-234632.
Recommendations / Next Steps
- Keep the 2.5.12 fix coverage for both
model/cbi/system/systime.luaandluci/apprpc/system.lua; regression tests should include both/admin/system/systimeand/rpc/appsystem.setclock. - Prefer eliminating shell interpolation entirely: call date-setting functionality without
/bin/sh, or strictly parse time input into numeric year/month/day/hour/min/sec components before execution. - Add a centralized helper for time-setting input validation so future LuCI, RPC, mobile-app, or setup-wizard paths cannot reintroduce separate quoting logic.
- Add negative tests for quotes, semicolons, backticks, pipes, redirection,
$(), newlines, and encoded variants for every administrative endpoint that reaches shell execution.
Additional Notes
- Idempotency was confirmed by running
bundle/vuln_variant/reproduction_steps.shtwice; both runs completed and produced the same verdict. - This is a meaningful alternate entrypoint but not a fixed-version bypass. The coding stage should treat it as evidence that the complete fix must cover all time-setting APIs, not only the originally reported CBI page.
CVE-2026-32833 Reproduction Transcript
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Full session Replay every step — scrub the timeline or play it back.
Artifacts and Evidence for CVE-2026-32833
Scripts, logs, diffs, and output captured during the reproduction.
How to Fix CVE-2026-32833
Upgrade Cudy LT300 V3 firmware · firmware to 2.5.12 (released 20-May-2026) or later.
FAQ: CVE-2026-32833
How does the CVE-2026-32833 command injection work?
cbid.system.ntp.current parameter, breaking out of the date -s '...' shell invocation and executing arbitrary commands in the router firmware context.Which Cudy LT300 firmware versions are affected by CVE-2026-32833, and where is it fixed?
How severe is CVE-2026-32833?
How can I reproduce CVE-2026-32833?
References for CVE-2026-32833
Authoritative sources for CVE-2026-32833 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.