CVE-2024-9977
moderateOS Command Injection in MitraStar GPT-2541GNAC Router Firewall Page
CVE-2024-9977 is an OS command injection flaw (CWE-78) in the Firewall Settings Page of the MitraStar GPT-2541GNAC DSL gateway, specifically in the /cgi-bin/settings-firewall.cgi script, where the SrcInterface argument is manipulated and passed into a system command. An attacker triggers it remotely by submitting a crafted SrcInterface value to that endpoint; the source classified the bug as critical, while the published CVSS 4.0 score is 5.1 (medium) with PR:H, indicating privileged/administrative access to the gateway's web interface is required and rated impact on confidentiality, integrity and availability is limited. Successful exploitation yields arbitrary command execution on the gateway with the web service's privileges, which on an ISP-supplied router can enable traffic manipulation or a foothold into the subscriber's LAN. Only the GPT-2541GNAC running firmware BR_g5.6_1.11(WVK.0)b26 is confirmed affected; these gateways are typically provisioned by internet service providers, so ISPs and their subscribers running this model are the exposed population. The exploit has been publicly disclosed and may be used, though no standalone PoC is catalogued and the issue is not yet in CISA KEV; EPSS assigns a 22.9% probability of exploitation within 30 days (98th percentile), and vendor notification was hampered by a broken contact email, so a patch may not be widely available yet.
What to do: Audit any GPT-2541GNAC gateways you manage for firmware BR_g5.6_1.11(WVK.0)b26 and restrict the web management interface so /cgi-bin/settings-firewall.cgi is not reachable from untrusted networks (e.g., disable WAN-side HTTP/HTTPS management or apply source-IP restrictions). Because the vendor's contact address was failing at disclosure, monitor MitraStar or your ISP support channel for corrected firmware and apply it promptly rather than waiting for an automatic push; given the 98th-percentile EPSS, treat internet-exposed units as likely targets.
| MitraStar GPT-2541GNAC (DSL gateway) | BR_g5.6_1.11(WVK.0)b26 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component Firewall Settings Page. The manipulation of the argument SrcInterface leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.