PT-2026-67388 · Gl.Inet · Gl-Mt3000
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GL.iNet GL-MT3000 versions prior to 4.4.6
Description
The Logread Lua RPC plugin contains a command injection flaw. A remote attacker can exploit this by manipulating the
module argument within the logread.get system log() function located in the /usr/lib/oui-httpd/rpc/logread file.Recommendations
Update GL.iNet GL-MT3000 to version 4.4.6 or later.
As a temporary workaround, restrict access to the Logread Lua RPC plugin to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gl-Mt3000