PT-2023-19503 · Gl.Inet · Gl-E750 Mudi

Published

2023-06-21

·

Updated

2024-12-06

·

CVE-2023-24261

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GL.iNET GL-E750 Mudi versions prior to v3.216
Description A vulnerability in the software allows authenticated attackers to execute arbitrary code via a crafted POST request.
Recommendations For versions prior to v3.216, update to firmware version v3.216 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-24261

Affected Products

Gl-E750 Mudi