Authentication Bypass Vulnerability in GL-iNet Devices
CVE-2024-45261

8HIGH

Key Information:

Vendor

GL-iNet

Vendor
CVE Published:
24 October 2024

What is CVE-2024-45261?

A vulnerability has been discovered in certain GL-iNet devices, including the MT6000, MT3000, MT2500, AXT1800, and AX1800 running version 4.6.2. This issue arises from the generation of session identifiers (SIDs) that are not properly linked to individual users, leading to a potential user authentication bypass. Attackers can exploit this flaw to create a valid SID, allowing them to bypass necessary authentication mechanisms, escalate user privileges, and gain unauthorized access to system controls and sensitive information.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.