Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech Conduit AEP (models mtcdt / mtcdtip / mtcdtiphp), IoT gateways running mLinux on ARM 32-bit. Type: authenticated OS command injection (CWE-78) through the uploaded filename of the admin-only upload_config command. The management API is served by lighttpd on TCP 8080 and proxied to the proprietary FastCGI daemon /usr/bin/rcell_api.
[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)
About this summary. This is a short, independently written summary of an article first published by Full Disclosure. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/fulldisclosure/2026/Sep/77
Source attribution: headline and facts are from Full Disclosure (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.


