github.com
https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthorized%20Access%20to%20File%20Download%20and%20Upload%20Interfaces.md CVE-2024-45260
HIGH
Record summary
CVE-2024-45260 has a selected CVSS score of 8.0 (high).
Description
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
gl-b3000_firmwareBrowse gl-inet / gl-b3000_firmwareDefault status: unknown | CVE List | 4.5.18 to < 4.5.19 | affected |
gl-mt6000_firmwareBrowse gl-inet / gl-mt6000_firmwareDefault status: unknown | CVE List | 4.6.2 to < 4.6.4 | affected |
gl-x300b_firmwareBrowse gl-inet / gl-x300b_firmwareDefault status: unknown | CVE List | 4.5.17 to < 4.5.18 | affected |
gl-x750_firmwareBrowse gl-inet / gl-x750_firmwareDefault status: unknown | CVE List | 4.3.18 to < 4.3.19 | affected |
gl-xe300_firmwareBrowse gl-inet / gl-xe300_firmwareDefault status: unknown | CVE List | 4.4.9 to < 4.4.10 | affected |
| 4.3.17 to < 4.3.18 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45260