PT-2025-17958 · Gl.Inet · Gl-Be3600 Slate 7+22

Gan3F

+1

·

Published

2025-04-26

·

Updated

2025-05-01

·

CVE-2025-2851

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GL.iNet GL-A1300 Slate Plus version 4.x GL.iNet GL-AR300M16 Shadow version 4.x GL.iNet GL-AR300M Shadow version 4.x GL.iNet GL-AR750 Creta version 4.x GL.iNet GL-AR750S-EXT Slate version 4.x GL.iNet GL-AX1800 Flint version 4.x GL.iNet GL-AXT1800 Slate AX version 4.x GL.iNet GL-B1300 Convexa-B version 4.x GL.iNet GL-B3000 Marble version 4.x GL.iNet GL-BE3600 Slate 7 version 4.x GL.iNet GL-E750 version 4.x GL.iNet GL-E750V2 Mudi version 4.x GL.iNet GL-MT300N-V2 Mango version 4.x GL.iNet GL-MT1300 Beryl version 4.x GL.iNet GL-MT2500 Brume 2 version 4.x GL.iNet GL-MT3000 Beryl AX version 4.x GL.iNet GL-MT6000 Flint 2 version 4.x GL.iNet GL-SFT1200 Opal version 4.x GL.iNet GL-X300B Collie version 4.x GL.iNet GL-X750 Spitz version 4.x GL.iNet GL-X3000 Spitz AX version 4.x GL.iNet GL-XE300 Puli version 4.x GL.iNet GL-XE3000 Puli AX version 4.x
Description A critical vulnerability has been found in the RPC Handler component of the affected GL.iNet devices. The issue is related to an unknown function of the file plugins.so, which leads to a buffer overflow when manipulated.
Recommendations To resolve the issue, it is recommended to upgrade the affected component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-2851

Affected Products

Gl-A1300 Slate Plus
Gl-Ar300M Shadow
Gl-Ar300M16 Shadow
Gl-Ar750 Creta
Gl-Ar750S-Ext Slate
Gl-Ax1800 Flint
Gl-Axt1800 Slate Ax
Gl-B1300 Convexa-B
Gl-B3000 Marble
Gl-Be3600 Slate 7
Gl-E750
Gl-E750V2 Mudi
Gl-Mt1300 Beryl
Gl-Mt2500 Brume 2
Gl-Mt3000 Beryl Ax
Gl-Mt300N-V2 Mango
Gl-Mt6000 Flint 2
Gl-Sft1200 Opal
Gl-X3000 Spitz Ax
Gl-X300B Collie
Gl-X750 Spitz
Gl-Xe300 Puli
Gl-Xe3000 Puli Ax