CVE-2024-45260

EUVD-2024-41396
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
gl-inetmt6000_firmware
4.6.2
gl-inetb1300_firmware
4.3.17
gl-inetmt2500_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetaxt1800_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetax1800_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetb3000_firmware
4.5.18
gl-ineta1300_firmware
4.5.17
gl-inetx300b_firmware
4.5.17
gl-inetx3000_firmware
4.4.9
gl-inetxe3000_firmware
4.4.9
gl-inetx750_firmware
4.3.18
gl-inetsft1200_firmware
4.3.18
gl-inetmt1300_firmware
4.3.18
gl-inete750_firmware
4.3.17
gl-inetxe300_firmware
4.3.17
gl-inetar750_firmware
4.3.17
gl-inetar750s_firmware
4.3.17
gl-inetar300m_firmware
4.3.17
gl-inetmt300n-v2_firmware
4.3.17
gl-inetmt3000_firmware
4.6.2
gl-inetar300m16_firmware
4.3.17
𝑥
= Vulnerable software versions