ZeroHour

CVE-2024-9977

moderate

OS Command Injection in MitraStar GPT-2541GNAC Router Firewall Page

CVSS 4.0
5.1 medium
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2024-9977 is an OS command injection flaw (CWE-78) in the Firewall Settings Page of the MitraStar GPT-2541GNAC DSL gateway, specifically in the /cgi-bin/settings-firewall.cgi script, where the SrcInterface argument is manipulated and passed into a system command. An attacker triggers it remotely by submitting a crafted SrcInterface value to that endpoint; the source classified the bug as critical, while the published CVSS 4.0 score is 5.1 (medium) with PR:H, indicating privileged/administrative access to the gateway's web interface is required and rated impact on confidentiality, integrity and availability is limited. Successful exploitation yields arbitrary command execution on the gateway with the web service's privileges, which on an ISP-supplied router can enable traffic manipulation or a foothold into the subscriber's LAN. Only the GPT-2541GNAC running firmware BR_g5.6_1.11(WVK.0)b26 is confirmed affected; these gateways are typically provisioned by internet service providers, so ISPs and their subscribers running this model are the exposed population. The exploit has been publicly disclosed and may be used, though no standalone PoC is catalogued and the issue is not yet in CISA KEV; EPSS assigns a 22.9% probability of exploitation within 30 days (98th percentile), and vendor notification was hampered by a broken contact email, so a patch may not be widely available yet.

What to do: Audit any GPT-2541GNAC gateways you manage for firmware BR_g5.6_1.11(WVK.0)b26 and restrict the web management interface so /cgi-bin/settings-firewall.cgi is not reachable from untrusted networks (e.g., disable WAN-side HTTP/HTTPS management or apply source-IP restrictions). Because the vendor's contact address was failing at disclosure, monitor MitraStar or your ISP support channel for corrected firmware and apply it promptly rather than waiting for an automatic push; given the 98th-percentile EPSS, treat internet-exposed units as likely targets.

Affected
MitraStar GPT-2541GNAC (DSL gateway)BR_g5.6_1.11(WVK.0)b26
Estimated exposure
moderatelikely thousands to low tens of thousands of internet-exposed units (est.; no published install counts) — No install counts are published for this model, but the GPT-2541GNAC is a single ISP-supplied DSL gateway typically deployed in regional ISP fleets, and only the fraction of units with the web management interface reachable from untrusted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component Firewall Settings Page. The manipulation of the argument SrcInterface leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.