7.5

CVE-2024-27356

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inetMt6000 Firmware Version4.5.5
   Gl-inetMt6000 Version-
Gl-inetXe3000 Firmware Version4.4.4
   Gl-inetXe3000 Version-
Gl-inetX3000 Firmware Version4.4.5
   Gl-inetX3000 Version-
Gl-inetMt3000 Firmware Version4.5.0
   Gl-inetMt3000 Version-
Gl-inetMt2500 Firmware Version4.5.0
   Gl-inetMt2500 Version-
Gl-inetAxt1800 Firmware Version4.5.0
   Gl-inetAxt1800 Version-
Gl-inetAx1800 Firmware Version4.5.0
   Gl-inetAx1800 Version-
Gl-inetA1300 Firmware Version4.5.0
   Gl-inetA1300 Version-
Gl-inetS200 Firmware Version4.1.4-0300
   Gl-inetS200 Version-
Gl-inetX750 Firmware Version4.3.7
   Gl-inetX750 Version-
Gl-inetSft1200 Firmware Version4.37
   Gl-inetSft1200 Version-
Gl-inetXe300 Firmware Version4.3.7
   Gl-inetXe300 Version-
Gl-inetMt1300 Firmware Version4.3.10
   Gl-inetMt1300 Version-
Gl-inetAr750 Firmware Version4.3.10
   Gl-inetAr750 Version-
Gl-inetAr750s Firmware Version4.3.10
   Gl-inetAr750s Version-
Gl-inetAr300m Firmware Version4.3.10
   Gl-inetAr300m Version-
Gl-inetAr300m16 Firmware Version4.3.10
   Gl-inetAr300m16 Version-
Gl-inetB1300 Firmware Version4.3.10
   Gl-inetB1300 Version-
Gl-inetMt300n-v2 Firmware Version4.3.10
   Gl-inetMt300n-v2 Version-
Gl-inetX300b Firmware Version3.217
   Gl-inetX300b Version-
Gl-inetS1300 Firmware Version3.216
   Gl-inetS1300 Version-
Gl-inetSf1200 Firmware Version3.216
   Gl-inetSf1200 Version-
Gl-inetMv1000 Firmware Version3.216
   Gl-inetMv1000 Version-
Gl-inetN300 Firmware Version3.216
   Gl-inetN300 Version-
Gl-inetB2200 Firmware Version3.216
   Gl-inetB2200 Version-
Gl-inetX1200 Firmware Version3.203
   Gl-inetX1200 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.18% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.