Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.
The vulnerability consists of improper permission verification in the gl_nas_sys authentication function. An attacker can send a specially crafted script to this function over the network without needing to possess any credentials. The function does not properly enforce required permissions, allowing a malicious payload to be passed and executed directly on the device.
An attacker gains the ability to execute arbitrary code on the vulnerable device (RCE), which may lead to complete takeover of the router, violation of data confidentiality and integrity, and disruption of its operation.
GL.iNet AX1800 firmware should be updated to version 4.5.0 or newer. Patches and details are available in the manufacturer's references on GitHub.
GL.iNet AX1800 with firmware version 4.0.0 to below 4.5.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGl Inet Gl Ax1800
HWGl-Inetall versionsGl Inet Gl Ax1800 Firmware
OSGl-Inet4.0.0 – 4.5.0 (excl.)
Related vulnerabilities
GL.iNet — Authentication Bypass w NGINX przez dopasowanie wzorców Lua
GL.iNet: privilege escalation przez interfejs add_user do uprawnień root
Nieprawidłowe uprawnienia w GL.iNet AX1800 umożliwiające zdalne wykonanie kodu
Buffer overflow w GL.iNet libglutil.so — zdalne wykonanie kodu
GL.iNet — instalacja dowolnego oprogramowania przez obejście weryfikacji po stronie klienta