CVE-2019-6272
HIGHGL.iNet GL-AR300M-Lite Firmware 2.27 - Remote Code Execution via login_cgi
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6272. PoCs published by Pasquale Turi.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in GL-AR300M-Lite firmware 2.27, including authenticated command injection (CVE-2019-6272, CVE-2019-6275), arbitrary file download (CVE-2019-6273), and directory traversal (CVE-2019-6274). The PoC uses authenticated sessions to inject commands via timezone settings and firmware update parameters.
Description
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in GL-AR300M-Lite firmware 2.27, including authenticated command injection (CVE-2019-6272, CVE-2019-6275), arbitrary file download (CVE-2019-6273), and directory traversal (CVE-2019-6274). The PoC uses authenticated sessions to inject commands via timezone settings and firmware update parameters.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H