Exploit Title: Cypress Solutions CTM-200 2.7.1 - Root Remote OS Command Injection Edb-ID: 50408 Author: LIQUIDWORM Type: REMOTE Platform: HARDWARE Date: 2021-10-13 Vulnerable App: Not specified Vendor: Cypress Solutions Inc. Product Web Page: https://www.cypress.bc.ca Affected Version: - 2.7.1.5659 - 2.0.5.3356-184 Summary: CTM-200 is the industrial cellular wireless gateway for fixed and mobile applications. The CTM-200 is a Linux based platform powered by ARM Cortex-A8 800 MHz superscalar processor. Tested On: GNU/Linux 2.6.32.25 (arm4tl) BusyBox v1.15.3 Vulnerability Discovered by: Gjoko 'LiquidWorm' Krstic (@zeroscience) Advisory ID: ZSL-2021-5687 Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5687.php Poc Post Request: Included in the screenshot