---
id: CVE-2026-32833
title: >-
  Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command
  injection vulnerability that allows authenticated attackers to execute
  arbitrary commands by injecting shell metacharacters into the
  cbid.system.ntp.current P…
summary: >-
  Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command
  injection vulnerability that allows authenticated attackers to execute
  arbitrary commands by injecting shell metacharacters into the
  cbid.system.ntp.current P…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-06-26'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32833'
references:
  - url: 'https://www.cudy.com/en-us/pages/download-center/lt300-3-0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cudy-lt300-os-command-injection-via-ntp-configuration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.02424
epssPercentile: 0.83488
ingestedAt: '2026-06-29T14:29:18.228Z'
---

## Overview

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. Attackers can submit malicious payloads through the NTP settings endpoint to achieve remote code execution on the underlying system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
