An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.
History

Mon, 24 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Gl-i
Gl-i x1200
Gl-inet
Gl-inet 0300
Gl-inet a1300
Gl-inet ar3000m
Gl-inet ar3000m16
Gl-inet ar750
Gl-inet ar750s
Gl-inet ax1800
Gl-inet axt1800
Gl-inet b1300
Gl-inet b2200
Gl-inet mt1300
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt300nv2
Gl-inet mv1000
Gl-inet n300
Gl-inet s1300
Gl-inet s200
Gl-inet sf1200
Gl-inet sft1200
Gl-inet x3000
Gl-inet x300b
Gl-inet x750
Gl-inet xe300
Gl-inet xe3000
Gl.inet
Gl.inet mt6000
Weaknesses CWE-200
CPEs cpe:2.3:a:gl-i:x1200:3.203:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:0300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:a1300:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:ar3000m16:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:ar3000m:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:ar750:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:ar750s:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:ax1800:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:axt1800:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:b1300:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:b2200:3.216:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:mt1300:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:mt2500:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:mt3000:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:mt300nv2:4.3.10:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:mv1000:3.216:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:n300:3.216:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:s1300:3.216:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:s200:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:sf1200:3.216:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:sft1200:4.3.7:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:x3000:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:x300b:3.217:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:x750:4.3.7:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:xe3000:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:gl-inet:xe300:4.3.7:*:*:*:*:*:*:*
cpe:2.3:h:gl.inet:MT6000:-:*:*:*:*:*:*:*
Vendors & Products Gl-i
Gl-i x1200
Gl-inet
Gl-inet 0300
Gl-inet a1300
Gl-inet ar3000m
Gl-inet ar3000m16
Gl-inet ar750
Gl-inet ar750s
Gl-inet ax1800
Gl-inet axt1800
Gl-inet b1300
Gl-inet b2200
Gl-inet mt1300
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt300nv2
Gl-inet mv1000
Gl-inet n300
Gl-inet s1300
Gl-inet s200
Gl-inet sf1200
Gl-inet sft1200
Gl-inet x3000
Gl-inet x300b
Gl-inet x750
Gl-inet xe300
Gl-inet xe3000
Gl.inet
Gl.inet mt6000
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-24T15:44:54.024Z

Reserved: 2024-02-25T00:00:00.000Z

Link: CVE-2024-27356

cve-icon Vulnrichment

Updated: 2024-08-02T00:34:51.986Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-27T01:15:07.197

Modified: 2025-03-24T16:15:17.823

Link: CVE-2024-27356

cve-icon Redhat

No data.