ZeroHour

CVE-2026-52484

moderate

Authenticated Command Injection RCE in MitraStar GPT-2742GX4X5v6-SV Router

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-52484 is an OS command injection flaw (CWE-78) in the MitraStar GPT-2742GX4X5v6-SV gateway running firmware GL_g2.5_100XNT0b23_3. An attacker who can authenticate to the device's management interface can inject arbitrary commands through the /cgi-bin/device-management-utilities-internet.cgi CGI endpoint, which passes insufficiently sanitized input to the underlying system shell. Successful exploitation yields arbitrary code execution on the router with full impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected devices are ISP-deployed GPON gateways, so the practical victims are subscribers whose routers run this specific firmware and whose credentials are default, weak, or already compromised. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Contact your ISP or MitraStar for a firmware update beyond GL_g2.5_100XNT0b23_3, as no patched version has been publicly specified. Immediately change any default or weak administrator credentials and disable remote/WAN-side management on the GPT-2742GX4X5v6-SV. Review device logs for unexpected requests to /cgi-bin/device-management-utilities-internet.cgi and reboot and re-verify the device if suspicious authenticated activity is found.

Affected
MitraStar GPT-2742GX4X5v6-SVGL_g2.5_100XNT0b23_3
Estimated exposure
moderate≈ tens of thousands of ISP-issued CPE units (estimate; no public device census available) — MitraStar GPT-series GPON gateways are mass-provisioned by ISPs to subscribers, so exposure tracks carrier fleet sizes, though the admin interface is typically reachable only from the LAN side, which limits internet-wide scanning…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.