CVE-2024-45261
24.10.2024, 21:15
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gl-inet | mt2500_firmware | 4.6.2 ≤ 𝑥 < 4.6.4 |
| gl-inet | axt1800_firmware | 4.6.2 ≤ 𝑥 < 4.6.4 |
| gl-inet | ax1800_firmware | 4.6.2 ≤ 𝑥 < 4.6.4 |
| gl-inet | b3000_firmware | 4.5.18 |
| gl-inet | a1300_firmware | 4.5.17 |
| gl-inet | x300b_firmware | 4.5.17 |
| gl-inet | x3000_firmware | 4.4.9 |
| gl-inet | xe3000_firmware | 4.4.9 |
| gl-inet | x750_firmware | 4.3.18 |
| gl-inet | sft1200_firmware | 4.3.18 |
| gl-inet | mt1300_firmware | 4.3.18 |
| gl-inet | e750_firmware | 4.3.17 |
| gl-inet | xe300_firmware | 4.3.17 |
| gl-inet | ar750_firmware | 4.3.17 |
| gl-inet | ar750s_firmware | 4.3.17 |
| gl-inet | ar300m_firmware | 4.3.17 |
| gl-inet | mt300n-v2_firmware | 4.3.17 |
| gl-inet | mt3000_firmware | 4.6.2 |
| gl-inet | ar300m16_firmware | 4.3.17 |
| gl-inet | mt6000_firmware | 4.6.2 |
| gl-inet | b1300_firmware | 4.3.17 |
𝑥
= Vulnerable software versions