Cybercriminals disrupted a steam turbine and water treatment systems at a Polish CHP facility by infiltrating their private cellular network, which the local grid operator relies on for accessing remote equipment This article explores rutx50 modem vulnerabilities. . The recovery process started around 7:30 in the morning when the intruders were still within the network's reach, ensuring that no disruptions occurred to either heat or power supply.

The route traversed a private APN managed by the distribution system operator: an access point name (APN) that allowed arbitrary devices on this network to communicate with one another, enabling an attacker to pivot from a compromised wind-farm network to control equipment at a combined heat and power (CHP) plant.

However, there were no corresponding specifications addressing the cellular router’s management interface, which was accessible through a separate Ethernet port linked to an internal VLAN behind the breached firewall. Two specific flaws in CISA’s 2023 Teltonika advisory, CVE-2023-32349 and CVE-2023-32350, both necessitate existing privileges on the device, while the RUTX50's modem vulnerabilities only cause denial of service. An unpublished flaw remains unconfirmed.

Approximately three hours after the last activity at the CHP facility, the intruder performed a factory reset on the Teltonika router, altered its administrator password, assigned it an unreachable IP address 127.0.0.1, then initiated a factory reset on the FortiGate, resulting in the loss of log data.