PT-2026-47168 · Gl.Inet · Gl-Mt3000
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GL.iNet GL-MT3000 versions prior to 4.7
Description
A remote command injection flaw exists in the MTK Backend component within the
iwinfo backend() function of the iwinfo.so file. The issue occurs when the device argument is manipulated, allowing an attacker to execute arbitrary commands remotely.Recommendations
Update to version 4.7.
Upgrade the affected MTK Backend component.
Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gl-Mt3000