GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint /cgi-bin/glc. This vulnerability allows unauthenticated attackers to execute arbitrary code or possibly a directory traversal via crafted JSON data.
The /cgi-bin/glc endpoint has improperly configured permissions that do not require authentication before processing requests. An attacker can send crafted JSON data to this endpoint, which leads to arbitrary code execution or enables path traversal on the device's file system. The vulnerability is classified as CWE-74 (injection) and CWE-75 (failure to sanitize special elements), indicating a lack of proper input validation and sanitization.
An attacker can remotely execute arbitrary code on the device (RCE) without needing any credentials, and also gain unauthorized access to any files on the system through path traversal, which may lead to full compromise of the router.
Apply patches available from the manufacturer according to references. It is recommended to monitor the manufacturer's repository at https://github.com/gl-inet/CVE-issues and update the firmware to patched versions as soon as possible. Until the update is applied, access to the device's administrative panel should be restricted to trusted networks only or remote access to the management interface should be disabled.
GL-iNet AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 firmware v4.3.11; MT3000/MT2500/AXT1800/AX1800/A1300/X300B firmware v4.5.16; XE300 firmware v4.3.16; E750 firmware v4.3.12; AP1300/S1300 firmware v4.3.13; XE3000/X3000 firmware v4.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGl Inet A1300
HWGl-Inetall versionsGl Inet A1300 Firmware
OSGl-Inet4.5.16Gl Inet Ap1300
HWGl-Inetall versionsGl Inet Ap1300 Firmware
OSGl-Inet3.217Gl Inet Ar300m
HWGl-Inetall versionsGl Inet Ar300m16
HWGl-Inetall versionsGl Inet Ar300m16 Firmware
OSGl-Inet4.3.11Gl Inet Ar300m Firmware
OSGl-Inet4.3.11Gl Inet Ar750
HWGl-Inetall versionsGl Inet Ar750 Firmware
OSGl-Inet4.3.11Gl Inet Ar750s
HWGl-Inetall versionsGl Inet Ar750s Firmware
OSGl-Inet4.3.11Gl Inet Ax1800
HWGl-Inetall versionsGl Inet Ax1800 Firmware
OSGl-Inet4.5.16Gl Inet Axt1800
HWGl-Inetall versionsGl Inet Axt1800 Firmware
OSGl-Inet4.5.16Gl Inet B1300
HWGl-Inetall versionsGl Inet B1300 Firmware
OSGl-Inet4.3.11Gl Inet B2200
HWGl-Inetall versionsGl Inet B2200 Firmware
OSGl-Inet3.216Gl Inet E750
HWGl-Inetall versionsGl Inet E750 Firmware
OSGl-Inet4.3.12Gl Inet Mt1300
HWGl-Inetall versionsGl Inet Mt1300 Firmware
OSGl-Inet4.3.11Gl Inet Mt2500
HWGl-Inetall versionsGl Inet Mt2500 Firmware
OSGl-Inet4.5.16Gl Inet Mt3000
HWGl-Inetall versionsGl Inet Mt3000 Firmware
OSGl-Inet4.5.16Gl Inet Mt300n V2
HWGl-Inetall versionsGl Inet Mt300n V2 Firmware
OSGl-Inet4.3.11
Related vulnerabilities
Command injection w GL-iNet GL-AR300M16 via set_config
Command injection w GL-iNet GL-AR300M16 via parametr module
Command injection w GL-iNet GL-AR300M16 — wykonanie dowolnych poleceń
Command injection w GL-iNet GL-AR300M16 — funkcja set_upgrade
RCE w firmware GL-iNet — obejście mechanizmu logowania