PT-2024-31517 · Gl.Inet · Mt3000+4

Published

2024-08-23

·

Updated

2025-10-15

·

CVE-2024-45260

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2
Description An issue was discovered that allows users who belong to unauthorized groups to invoke any interface of the device, thereby gaining complete control over it.
Recommendations For GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 version 4.6.2, restrict access to device interfaces to prevent unauthorized control. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-05698
CVE-2024-45260

Affected Products

Axt1800
Gl.Inet
Mt2500
Mt3000
Mt6000