Remote File Deletion Vulnerability in GL-iNet Devices
CVE-2024-45259

6.5MEDIUM

Key Information:

Vendor

GL-iNet

Vendor
CVE Published:
24 October 2024

What is CVE-2024-45259?

A vulnerability has been identified in various GL-iNet devices, specifically affecting versions of the MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. This issue enables attackers to intercept an HTTP request and modify the filename parameter in the download interface, which can lead to unauthorized file deletion on the affected devices. This poses a significant risk, as it allows malicious actors to delete critical files, potentially compromising the functionality of the devices.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.