CVE-2024-27356

EUVD-2024-24560
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
gl-inetmt6000_firmware
4.5.5
gl-inetxe3000_firmware
4.4.4
gl-inetx3000_firmware
4.4.5
gl-inetmt3000_firmware
4.5.0
gl-inetmt2500_firmware
4.5.0
gl-inetaxt1800_firmware
4.5.0
gl-inetax1800_firmware
4.5.0
gl-ineta1300_firmware
4.5.0
gl-inets200_firmware
4.1.4-0300
gl-inetx750_firmware
4.3.7
gl-inetsft1200_firmware
4.37
gl-inetxe300_firmware
4.3.7
gl-inetmt1300_firmware
4.3.10
gl-inetar750_firmware
4.3.10
gl-inetar750s_firmware
4.3.10
gl-inetar300m_firmware
4.3.10
gl-inetar300m16_firmware
4.3.10
gl-inetb1300_firmware
4.3.10
gl-inetmt300n-v2_firmware
4.3.10
gl-inetx300b_firmware
3.217
gl-inets1300_firmware
3.216
gl-inetsf1200_firmware
3.216
gl-inetmv1000_firmware
3.216
gl-inetn300_firmware
3.216
gl-inetb2200_firmware
3.216
gl-inetx1200_firmware
3.203
𝑥
= Vulnerable software versions