Impact
An OS command injection flaw exists in the NAS Command Service component that processes the file /usr/bin/gl_nas_sys. The flaw allows an attacker to execute arbitrary system commands, potentially taking full control of the device. The vulnerability is reported as capable of being exploited remotely.
Affected Systems
GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, and XE3000 running firmware 4.8.x are affected. Firmware 4.9.0 contains a fix that addresses the vulnerability.
Risk and Exploitability
The vulnerability scores a CVSS of 6.9, indicating medium to high severity. No EPSS data is publicly available, and the issue is not listed in the CISA KEV catalog. An attacker can likely trigger the injection through network access to the device, providing a remote exploit path with significant impact if successful.
OpenCVE Enrichment