# I-O Data UD-LT2 router flaws patched

Published: 2025-01-21 · Severity: medium · Sectors: telecommunications
Canonical: https://vorant.io/reports/3296c4e4-a567-5343-a2ec-eaa6fed76adb/i-o-data-ud-lt2-router-flaws-patched

> I-O Data's UD-LT2 LTE router has OS command injection and undocumented function vulnerabilities that let attackers run arbitrary commands or disable the firewall.

IPA disclosed three vulnerabilities affecting I-O Data's UD-LT2 hybrid LTE router running firmware Ver.1.00.008_SE or earlier. Two of the flaws (CVE-2025-20617 and CVE-2025-23237) are OS command injection vulnerabilities, while a third (CVE-2025-22450) is an undocumented function that could allow unauthorized access to device capabilities. Successful exploitation could allow an attacker to execute arbitrary OS commands, disable the device firewall, or alter device configuration settings.

The vendor has released firmware Ver.1.00.011_SE to address all three issues. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor-coordinated disclosure via JVN. Affected organizations and consumers using the UD-LT2 should apply the firmware update promptly to mitigate the risk of remote command execution and firewall bypass.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20617, CVE-2025-22450, CVE-2025-23237

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/20250122-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3296c4e4-a567-5343-a2ec-eaa6fed76adb/i-o-data-ud-lt2-router-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
