PT-2024-31518 · Gl.Inet · Gl-Inet Mt2500+3
Published
2024-08-23
·
Updated
2025-10-15
·
CVE-2024-45261
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GL-iNet MT6000 version 4.6.2
GL-iNet MT3000 version 4.6.2
GL-iNet MT2500 version 4.6.2
GL-iNet AXT1800 version 4.6.2
GL-iNet AX1800 version 4.6.2
Description
An issue was discovered on certain GL-iNet devices. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.
Recommendations
For GL-iNet MT6000 version 4.6.2, consider disabling the authentication mechanism that generates the SID until a patch is available.
For GL-iNet MT3000 version 4.6.2, restrict access to the application's authentication procedures to minimize the risk of exploitation.
For GL-iNet MT2500 version 4.6.2, avoid using the SID for authentication until the issue is resolved.
For GL-iNet AXT1800 version 4.6.2, consider implementing additional authentication measures to prevent privilege escalation.
For GL-iNet AX1800 version 4.6.2, restrict access to the application's authentication procedures to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gl-Inet Ax1800
Gl-Inet Mt2500
Gl-Inet Mt3000
Gl-Inet Mt6000