Remote Code Execution Vulnerability in GL-iNet Router Products
CVE-2024-39226
9.8CRITICAL
What is CVE-2024-39226?
The vulnerability in GL-iNet router products allows remote attackers to execute arbitrary shell commands via the s2s API. This issue arises when the routers process specifically crafted input without proper validation, enabling attackers to manipulate the device’s functionality and potentially gain unauthorized access to network resources. It affects various GL-iNet routers, including models AR750, AR750S, AR300M, and others, across multiple firmware versions. Users are advised to apply available updates and enhance their security configurations to mitigate potential risks.
