CVE-2026-52484
moderateAuthenticated Command Injection RCE in MitraStar GPT-2742GX4X5v6-SV Router
CVE-2026-52484 is an OS command injection flaw (CWE-78) in the MitraStar GPT-2742GX4X5v6-SV gateway running firmware GL_g2.5_100XNT0b23_3. An attacker who can authenticate to the device's management interface can inject arbitrary commands through the /cgi-bin/device-management-utilities-internet.cgi CGI endpoint, which passes insufficiently sanitized input to the underlying system shell. Successful exploitation yields arbitrary code execution on the router with full impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected devices are ISP-deployed GPON gateways, so the practical victims are subscribers whose routers run this specific firmware and whose credentials are default, weak, or already compromised. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Contact your ISP or MitraStar for a firmware update beyond GL_g2.5_100XNT0b23_3, as no patched version has been publicly specified. Immediately change any default or weak administrator credentials and disable remote/WAN-side management on the GPT-2742GX4X5v6-SV. Review device logs for unexpected requests to /cgi-bin/device-management-utilities-internet.cgi and reboot and re-verify the device if suspicious authenticated activity is found.
| MitraStar GPT-2742GX4X5v6-SV | GL_g2.5_100XNT0b23_3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.