VORANT. Threat Intelligence Sign in Get the full feed

I-O Data LTE routers exploited in the wild

high vulnerability telecommunications

Three vulnerabilities in I-O Data's UD-LT1/UD-LT1/EX LTE routers, including an OS command injection flaw, are being actively exploited to steal credentials and disable firewalls.

Japan's IPA issued an alert for three vulnerabilities affecting I-O Data's UD-LT1 and UD-LT1/EX hybrid LTE routers: improper access control (CVE-2024-45841), OS command injection (CVE-2024-47133), and an undocumented function (CVE-2024-52564). The advisory states that attacks exploiting these flaws have already been confirmed in the wild, and urges users to apply firmware updates and workarounds immediately.

Successful exploitation could allow an attacker to steal authentication credentials, execute arbitrary OS commands, disable the device firewall, and alter device configuration — effectively giving full remote control over the affected routers. CVE-2024-52564 (CVSS 7.5) is the most severe, followed by CVE-2024-47133 (7.2) and CVE-2024-45841 (6.5). Fixes for the access control and command injection issues are available in firmware version 2.2.0 for both affected models; a separate fix version addresses the undocumented function vulnerability.

Given the confirmed in-the-wild exploitation against internet-facing consumer/SOHO network hardware, administrators of these devices should prioritize firmware updates and review device configurations for unauthorized changes, particularly disabled firewall settings.

Mentioned in this report

Vulnerabilities CVE-2024-45841CVE-2024-47133CVE-2024-52564

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/20241204-jvn.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free