6.5

CVE-2024-45259

Exploit
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inetMt3000 Firmware Version4.6.2
   Gl-inetGl-mt3000 Version-
Gl-inetMt2500 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetMt2500 Version-
Gl-inetAxt1800 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetAxt1800 Version-
Gl-inetAx1800 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetAx1800 Version-
Gl-inetB3000 Firmware Version4.5.18
   Gl-inetB3000 Version-
Gl-inetA1300 Firmware Version4.5.17
   Gl-inetA1300 Version-
Gl-inetX300b Firmware Version4.5.17
   Gl-inetX300b Version-
Gl-inetX3000 Firmware Version4.4.9
   Gl-inetX3000 Version-
Gl-inetXe3000 Firmware Version4.4.9
   Gl-inetXe3000 Version-
Gl-inetX750 Firmware Version4.3.18
   Gl-inetX750 Version-
Gl-inetSft1200 Firmware Version4.3.18
   Gl-inetSft1200 Version-
Gl-inetMt1300 Firmware Version4.3.18
   Gl-inetMt1300 Version-
Gl-inetE750 Firmware Version4.3.17
   Gl-inetE750 Version-
Gl-inetXe300 Firmware Version4.3.17
   Gl-inetXe300 Version-
Gl-inetAr750 Firmware Version4.3.17
   Gl-inetAr750 Version-
Gl-inetAr750s Firmware Version4.3.17
   Gl-inetAr750s Version-
Gl-inetAr300m Firmware Version4.3.17
   Gl-inetAr300m Version-
Gl-inetAr300m16 Firmware Version4.3.17
   Gl-inetAr300m16 Version-
Gl-inetMt300n-v2 Firmware Version4.3.17
   Gl-inetMt300n-v2 Version-
Gl-inetB1300 Firmware Version4.3.17
   Gl-inetB1300 Version-
Gl-inetMt6000 Firmware Version4.6.2
   Gl-inetMt6000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.