CVE-2024-45262
HIGHGL-iNet Firmware - Path Traversal via /rpc Endpoint Params Parameter
Title source: llmDescription
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.
References (1)
Core 1
Core References
Scores
CVSS v3
8.8
EPSS
0.0065
EPSS Percentile
46.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (21)
gl-inet/a1300_firmware
4.5.17
gl-inet/ar300m16_firmware
4.3.17
gl-inet/ar300m_firmware
4.3.17
gl-inet/ar750_firmware
4.3.17
gl-inet/ar750s_firmware
4.3.17
gl-inet/ax1800_firmware
4.6.2 - 4.6.4
gl-inet/axt1800_firmware
4.6.2 - 4.6.4
gl-inet/b1300_firmware
4.3.17
gl-inet/b3000_firmware
4.5.18
gl-inet/e750_firmware
4.3.17
... and 11 more
Published
Oct 24, 2024
Tracked Since
Feb 18, 2026