# I-O Data LTE routers exploited in the wild

Published: 2024-12-17 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/db393884-b3db-5892-aab0-cd341b98846b/i-o-data-lte-routers-exploited-in-the-wild

> Three vulnerabilities in I-O Data's UD-LT1/UD-LT1/EX LTE routers, including an OS command injection flaw, are being actively exploited to steal credentials and disable firewalls.

Japan's IPA issued an alert for three vulnerabilities affecting I-O Data's UD-LT1 and UD-LT1/EX hybrid LTE routers: improper access control (CVE-2024-45841), OS command injection (CVE-2024-47133), and an undocumented function (CVE-2024-52564). The advisory states that attacks exploiting these flaws have already been confirmed in the wild, and urges users to apply firmware updates and workarounds immediately.

Successful exploitation could allow an attacker to steal authentication credentials, execute arbitrary OS commands, disable the device firewall, and alter device configuration — effectively giving full remote control over the affected routers. CVE-2024-52564 (CVSS 7.5) is the most severe, followed by CVE-2024-47133 (7.2) and CVE-2024-45841 (6.5). Fixes for the access control and command injection issues are available in firmware version 2.2.0 for both affected models; a separate fix version addresses the undocumented function vulnerability.

Given the confirmed in-the-wild exploitation against internet-facing consumer/SOHO network hardware, administrators of these devices should prioritize firmware updates and review device configurations for unauthorized changes, particularly disabled firewall settings.

## Mentioned in this report

- Vulnerabilities: CVE-2024-45841, CVE-2024-47133, CVE-2024-52564

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/20241204-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/db393884-b3db-5892-aab0-cd341b98846b/i-o-data-lte-routers-exploited-in-the-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
