PT-2026-67144 · Gl.Inet · Be9300+10
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GL.iNet MT3000 versions prior to 20260707
GL.iNet MT6000 versions prior to 20260707
GL.iNet BE9300 versions prior to 20260707
GL.iNet BE3600 versions prior to 20260707
GL.iNet MT3600BE versions prior to 20260707
GL.iNet E5800 versions prior to 20260707
GL.iNet BE6500 versions prior to 20260707
GL.iNet MT5000 versions prior to 20260707
GL.iNet X3000 versions prior to 20260707
GL.iNet XE3000 versions prior to 20260707
GL.iNet MT2500 versions prior to 20260707
Description
A remote attack can trigger a heap-based buffer overflow, which occurs when a program writes more data to a heap memory area than it can hold, potentially leading to crashes or arbitrary code execution. This issue exists within the APPS-NAS Module, specifically in the
nas-web.get file list() function.Recommendations
Update MT3000 to version 20260707 or later.
Update MT6000 to version 20260707 or later.
Update BE9300 to version 20260707 or later.
Update BE3600 to version 20260707 or later.
Update MT3600BE to version 20260707 or later.
Update E5800 to version 20260707 or later.
Update BE6500 to version 20260707 or later.
Update MT5000 to version 20260707 or later.
Update X3000 to version 20260707 or later.
Update XE3000 to version 20260707 or later.
Update MT2500 to version 20260707 or later.
As a temporary workaround, restrict access to the
nas-web.get file list() function within the APPS-NAS Module.Exploit
Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Be3600
Be6500
Be9300
E5800
Mt2500
Mt3000
Mt3600Be
Mt5000
Mt6000
X3000
Xe3000