Skip to finding
important · Cellular — Tozed Router

A rogue LTE base station can make Tozed X300 routers execute shell commands as root.

Affects

Tozed ZLT X300 and X300A 5G CPE routers, cellular gateways running an aarch64 OpenWrt-derived firmware.

After a router attaches to the rogue cellular network, the attacker can impersonate the carrier’s TR-069 server and supply IPPingDiagnostics.Host.

Detail and 2 sources

netcwmpd inserts that value into a command passed to system_by_root() without validation, producing uid 0 shell execution. The researcher reproduced the chain on owned hardware and a private LTE network.

No patch is available.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026