peter bassill · operator
$ cve CVE-2024-27356 JSON

CVE-2024-27356 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 23.9% (pctl 98)

Patch early

A public exploit exists.

Description

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS23.91% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2024-02-27
Last modified2026-06-17

Affected (40)

VendorProduct
gl-ineta1300
gl-ineta1300 firmware
gl-inetar300m
gl-inetar300m firmware
gl-inetar300m16
gl-inetar300m16 firmware
gl-inetar750
gl-inetar750 firmware
gl-inetar750s
gl-inetar750s firmware
gl-inetax1800
gl-inetax1800 firmware
gl-inetaxt1800
gl-inetaxt1800 firmware
gl-inetb1300
gl-inetb1300 firmware
gl-inetmt1300
gl-inetmt1300 firmware
gl-inetmt2500
gl-inetmt2500 firmware
gl-inetmt3000
gl-inetmt3000 firmware
gl-inetmt300n-v2
gl-inetmt300n-v2 firmware
gl-inetmt6000
gl-inetmt6000 firmware
gl-inets200
gl-inets200 firmware
gl-inetsft1200
gl-inetsft1200 firmware
gl-inetx3000
gl-inetx3000 firmware
gl-inetx300b
gl-inetx300b firmware
gl-inetx750
gl-inetx750 firmware
gl-inetxe300
gl-inetxe300 firmware
gl-inetxe3000
gl-inetxe3000 firmware

Public exploits

SourceTitleDate
exploit-dbGL-iNet MT6000 4.5.5 - Arbitrary File Download2024-04-02

References

→ the Explorer  ·  watch your stack  ·  NVD