7.5

CVE-2024-28077

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inetMt6000 Firmware Version4.5.6
   Gl-inetMt6000 Version-
Gl-inetX3000 Firmware Version4.4.6
   Gl-inetX3000 Version-
Gl-inetXe3000 Firmware Version4.4.4
   Gl-inetXe3000 Version-
Gl-inetA1300 Firmware Version4.5.0
   Gl-inetA1300 Version-
Gl-inetAx1800 Firmware Version4.5.0
   Gl-inetAx1800 Version-
Gl-inetAxt1800 Firmware Version4.5.0
   Gl-inetAxt1800 Version-
Gl-inetMt2500 Firmware Version4.5.0
   Gl-inetMt2500 Version-
Gl-inetMt3000 Firmware Version4.5.0
   Gl-inetMt3000 Version-
Gl-inetXe300 Firmware Version4.3.16
   Gl-inetXe300 Version-
Gl-inetX750 Firmware Version4.3.7
   Gl-inetX750 Version-
Gl-inetSft1200 Firmware Version4.3.7
   Gl-inetSft1200 Version-
Gl-inetAr300m Firmware Version4.3.10
   Gl-inetAr300m Version-
Gl-inetAr300m16 Firmware Version4.3.10
   Gl-inetAr300m16 Version-
Gl-inetAr750 Firmware Version4.3.10
   Gl-inetAr750 Version-
Gl-inetAr750s Firmware Version4.3.10
   Gl-inetAr750s Version-
Gl-inetB1300 Firmware Version4.3.10
   Gl-inetB1300 Version-
Gl-inetMt1300 Firmware Version4.3.10
   Gl-inetMt1300 Version-
Gl-inetMt300n-v2 Firmware Version4.3.10
   Gl-inetMt300n-v2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.381
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.