- EPSS 0.02%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 15.10.2025 17:54:46
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication....
CVE-2024-45262
- EPSS 0.1%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 15.10.2025 17:54:36
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to e...
CVE-2024-45263
- EPSS 0.06%
- Veröffentlicht 24.10.2024 21:15:12
- Zuletzt bearbeitet 29.09.2025 15:02:17
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to informatio...
- EPSS 3.55%
- Veröffentlicht 24.10.2024 21:15:11
- Zuletzt bearbeitet 15.10.2025 17:55:07
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
CVE-2024-45259
- EPSS 0.03%
- Veröffentlicht 24.10.2024 20:15:04
- Zuletzt bearbeitet 15.10.2025 17:55:27
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.
CVE-2023-31473
- EPSS 2.47%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:33
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the softwar...
CVE-2023-31475
- EPSS 23.68%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:33
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the s...
CVE-2023-31477
- EPSS 0.31%
- Veröffentlicht 11.05.2023 02:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:34
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB pat...
CVE-2023-31471
- EPSS 0.62%
- Veröffentlicht 10.05.2023 15:15:10
- Zuletzt bearbeitet 27.01.2025 20:15:31
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-si...
CVE-2023-31478
- EPSS 82.64%
- Veröffentlicht 09.05.2023 23:15:09
- Zuletzt bearbeitet 29.01.2025 21:15:20
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.