PT-2024-31515 · Gl.Inet · Mt3000+4

Published

2024-10-24

·

Updated

2025-10-15

·

CVE-2024-45259

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2
Description An issue was discovered that allows deletion of any file on the device by intercepting an HTTP request and modifying the filename property in the download interface.
Recommendations For GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2, consider restricting access to the download interface as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45259

Affected Products

Axt1800
Gl.Inet
Mt2500
Mt3000
Mt6000