PT-2026-49144 · Gl.Inet · Gl-Mt3000
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GL.iNet GL-MT3000 versions prior to 4.7
Description
A command injection flaw exists in the Tor Proxy Service Configuration Handler. The issue is located within the
replace country() function in the /usr/lib/oui-httpd/rpc/tor library, allowing a remote attacker to execute arbitrary commands.Recommendations
Upgrade to version 4.7.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gl-Mt3000