8.8

CVE-2024-45263

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inetMt6000 Firmware Version4.6.2
   Gl-inetMt6000 Version-
Gl-inetMt3000 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetGl-mt3000 Version-
Gl-inetMt2500 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetMt2500 Version-
Gl-inetAxt1800 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetAxt1800 Version-
Gl-inetAx1800 Firmware Version >= 4.6.2 < 4.6.4
   Gl-inetAx1800 Version-
Gl-inetB3000 Firmware Version4.5.18
   Gl-inetB3000 Version-
Gl-inetA1300 Firmware Version4.5.17
   Gl-inetA1300 Version-
Gl-inetX300b Firmware Version4.5.17
   Gl-inetX300b Version-
Gl-inetX3000 Firmware Version4.4.9
   Gl-inetX3000 Version-
Gl-inetXe3000 Firmware Version4.4.9
   Gl-inetXe3000 Version-
Gl-inetX750 Firmware Version4.3.18
   Gl-inetX750 Version-
Gl-inetSft1200 Firmware Version4.3.18
   Gl-inetSft1200 Version-
Gl-inetMt1300 Firmware Version4.3.18
   Gl-inetMt1300 Version-
Gl-inetE750 Firmware Version4.3.17
   Gl-inetE750 Version-
Gl-inetXe300 Firmware Version4.3.17
   Gl-inetXe300 Version-
Gl-inetAr750 Firmware Version4.3.17
   Gl-inetAr750 Version-
Gl-inetAr750s Firmware Version4.3.17
   Gl-inetAr750s Version-
Gl-inetAr300m Firmware Version4.3.17
   Gl-inetAr300m Version-
Gl-inetAr300m16 Firmware Version4.3.17
   Gl-inetAr300m16 Version-
Gl-inetB1300 Firmware Version4.3.17
   Gl-inetB1300 Version-
Gl-inetMt300n-v2 Firmware Version4.3.17
   Gl-inetMt300n-v2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.