CVE-2024-45263

EUVD-2024-41399
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
gl-inetmt6000_firmware
4.6.2
gl-inetmt3000_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetmt2500_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetaxt1800_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetax1800_firmware
4.6.2 ≤
𝑥
< 4.6.4
gl-inetb3000_firmware
4.5.18
gl-ineta1300_firmware
4.5.17
gl-inetx300b_firmware
4.5.17
gl-inetx3000_firmware
4.4.9
gl-inetxe3000_firmware
4.4.9
gl-inetx750_firmware
4.3.18
gl-inetsft1200_firmware
4.3.18
gl-inetmt1300_firmware
4.3.18
gl-inete750_firmware
4.3.17
gl-inetxe300_firmware
4.3.17
gl-inetar750_firmware
4.3.17
gl-inetar750s_firmware
4.3.17
gl-inetar300m_firmware
4.3.17
gl-inetar300m16_firmware
4.3.17
gl-inetb1300_firmware
4.3.17
gl-inetmt300n-v2_firmware
4.3.17
𝑥
= Vulnerable software versions