CVE-2025-29570

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:szlbt:lbt-t300-t400_firmware:3.2:*:*:*:*:*:*:*
cpe:2.3:h:szlbt:lbt-t300-t400:-:*:*:*:*:*:*:*

History

20 Aug 2025, 02:50

Type Values Removed Values Added
CPE cpe:2.3:h:szlbt:lbt-t300-t400:-:*:*:*:*:*:*:*
cpe:2.3:o:szlbt:lbt-t300-t400_firmware:3.2:*:*:*:*:*:*:*
References () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/firmwareupdate.md - () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/firmwareupdate.md - Exploit, Third Party Advisory
First Time Szlbt
Szlbt lbt-t300-t400
Szlbt lbt-t300-t400 Firmware

07 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) Un problema en Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 permite que un atacante local escale privilegios a través de la función tftp_image_check de un binario llamado rc.

03 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 20:15

Updated : 2025-08-20 02:50


NVD link : CVE-2025-29570

Mitre link : CVE-2025-29570

CVE.ORG link : CVE-2025-29570


JSON object : View

Products Affected

szlbt

  • lbt-t300-t400_firmware
  • lbt-t300-t400
CWE
CWE-276

Incorrect Default Permissions