PT-2024-31515 · Gl.Inet · Mt3000+4
Published
2024-10-24
·
Updated
2025-10-15
·
CVE-2024-45259
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2
Description
An issue was discovered that allows deletion of any file on the device by intercepting an HTTP request and modifying the
filename property in the download interface.Recommendations
For GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2, consider restricting access to the download interface as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axt1800
Gl.Inet
Mt2500
Mt3000
Mt6000