# I-O DATA UD-LT2 router flaws enable RCE

Published: 2025-01-21 · Severity: medium
Canonical: https://vorant.io/reports/3296c4e4-a567-5343-a2ec-eaa6fed76adb/i-o-data-ud-lt2-router-flaws-enable-rce

> Three vulnerabilities in I-O DATA's UD-LT2 hybrid LTE router allow attackers to execute arbitrary OS commands and disable firewall protections.

Japan's IPA has disclosed three vulnerabilities in I-O DATA's UD-LT2 hybrid LTE router affecting firmware version 1.00.008_SE and earlier. The flaws include two OS command injection vulnerabilities (CVE-2025-20617, CVE-2025-23237) and an undocumented feature vulnerability (CVE-2025-22450). Exploitation could allow attackers to execute arbitrary operating system commands or disable the device's firewall and modify its configuration.

The vulnerabilities carry CVSS v3 scores ranging from 6.6 to 7.5, with CVE-2025-22450 rated as the most severe at 7.5. All three issues have been addressed in firmware version 1.00.011_SE, which I-O DATA has released to remediate the flaws.

Organizations using affected UD-LT2 routers should update to the patched firmware version immediately. These types of router vulnerabilities are commonly targeted for botnet recruitment and lateral movement within networks, particularly when deployed in small office or home office environments.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20617, CVE-2025-22450, CVE-2025-23237

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/20250122-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3296c4e4-a567-5343-a2ec-eaa6fed76adb/i-o-data-ud-lt2-router-flaws-enable-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
