CVE-2024-45262

HIGHCVSS 8.8/10EPSS 0.65%

Last modified

CVE-2024-45262 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.

Description

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.65%

46.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Gl-InetMt2500 Firmware>= 4.6.2, < 4.6.4
Gl-InetAxt1800 Firmware>= 4.6.2, < 4.6.4
Gl-InetAx1800 Firmware>= 4.6.2, < 4.6.4
Gl-InetB3000 Firmware4.5.18
Gl-InetA1300 Firmware4.5.17
Gl-InetX300b Firmware4.5.17
Gl-InetX3000 Firmware4.4.9
Gl-InetXe3000 Firmware4.4.9
Gl-InetX750 Firmware4.3.18
Gl-InetSft1200 Firmware4.3.18
Gl-InetMt1300 Firmware4.3.18
Gl-InetE750 Firmware4.3.17
Gl-InetXe300 Firmware4.3.17
Gl-InetAr750 Firmware4.3.17
Gl-InetAr750s Firmware4.3.17
Gl-InetAr300m Firmware4.3.17
Gl-InetMt300n-V2 Firmware4.3.17
Gl-InetMt6000 Firmware4.6.2
Gl-InetB1300 Firmware4.3.17
Gl-InetMt3000 Firmware4.6.2
Gl-InetAr300m16 Firmware4.3.17

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-45262?
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.
How severe is CVE-2024-45262?
CVE-2024-45262 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2024-45262?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-45262?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST