PT-2026-73200 · Gl.Inet · X3000+15
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GL.iNet A1300 versions prior to 4.8.x
GL.iNet AX1800 versions prior to 4.8.x
GL.iNet AXT1800 versions prior to 4.8.x
GL.iNet BE1400 versions prior to 4.8.x
GL.iNet BE3600 versions prior to 4.8.x
GL.iNet BE6500 versions prior to 4.8.x
GL.iNet BE9300 versions prior to 4.8.x
GL.iNet BE10000 versions prior to 4.8.x
GL.iNet E5800 versions prior to 4.8.x
GL.iNet MT2500 versions prior to 4.8.x
GL.iNet MT3000 versions prior to 4.8.x
GL.iNet MT3600BE versions prior to 4.8.x
GL.iNet MT5000 versions prior to 4.8.x
GL.iNet MT6000 versions prior to 4.8.x
GL.iNet X2000 versions prior to 4.8.x
GL.iNet X3000 versions prior to 4.8.x
GL.iNet XE3000 versions prior to 4.8.x
Description
A weakness in the Wi-Fi Timer Power-Schedule Feature allows for remote OS command injection. This occurs when the
switch power or restore power arguments are manipulated.Recommendations
Update GL.iNet A1300 to version 4.8.x or later.
Update GL.iNet AX1800 to version 4.8.x or later.
Update GL.iNet AXT1800 to version 4.8.x or later.
Update GL.iNet BE1400 to version 4.8.x or later.
Update GL.iNet BE3600 to version 4.8.x or later.
Update GL.iNet BE6500 to version 4.8.x or later.
Update GL.iNet BE9300 to version 4.8.x or later.
Update GL.iNet BE10000 to version 4.8.x or later.
Update GL.iNet E5800 to version 4.8.x or later.
Update GL.iNet MT2500 to version 4.8.x or later.
Update GL.iNet MT3000 to version 4.8.x or later.
Update GL.iNet MT3600BE to version 4.8.x or later.
Update GL.iNet MT5000 to version 4.8.x or later.
Update GL.iNet MT6000 to version 4.8.x or later.
Update GL.iNet X2000 to version 4.8.x or later.
Update GL.iNet X3000 to version 4.8.x or later.
Update GL.iNet XE3000 to version 4.8.x or later.
As a temporary workaround, restrict access to the Wi-Fi Timer Power-Schedule Feature to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A1300
Axt1800
Be10000
Be1400
Be3600
Be6500
Be9300
E5800
Mt2500
Mt3000
Mt3600Be
Mt5000
Mt6000
X2000
X3000
Xe3000