Szlbt manufactures a line of embedded networking and storage appliances, primarily the LBT-T300 and T400 series and related firmware, that serve in infrastructure and edge-deployment contexts. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate consistently around memory-safety and configuration issues including classic and stack-based buffer overflows, bounds-checking failures, and improper default permissions that are characteristic of embedded device firmware. Defenders should prioritize inventory and patching of affected appliances, particularly where they are internet-accessible or bridge critical network segments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Szlbt over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40535CRITICAL Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function. | Jul 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-50469CRITICAL Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi. | Dec 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-29243CRITICAL Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi. | Mar 21, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-8019HIGH A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected by this issue is the function sub_40B6F0 of the file at/appy | Jul 22, 2025 | 8.8 | 22 | NO | NO |
CVE-2025-7077HIGH A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This affects the function config_3g_para of the file /appy.cgi. Th | Jul 6, 2025 | 8.8 | 22 | NO | NO |
CVE-2025-29570HIGH An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc. | Apr 3, 2025 | 7.8 | 22 | NO | NO |
CVE-2024-32324HIGH Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code via the vpn_client_ip variable of the co | Apr 25, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-47307HIGH Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode param | Nov 30, 2023 | 7.5 | 20 | NO | NO |
CVE-2024-40536MEDIUM Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the config_3g_para function. | Jul 16, 2024 | 5.3 | 19 | NO | NO |
CVE-2024-28447MEDIUM Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cgi. | Mar 19, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Szlbt.
Media articles that mention a CVE ID that affects a product developed by Szlbt — matched by CVE ID, not by vendor name.