ZeroHour

CVE-2024-45262

PoC
CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
Description

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

Vendors
gl-inet
Products
mt2500 firmware, axt1800 firmware, ax1800 firmware, b3000 firmware, a1300 firmware, x300b firmware, x3000 firmware, xe3000 firmware, x750 firmware, sft1200 firmware, mt1300 firmware, e750 firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.