Impact
Authenticated users can craft a POST request to the /cgi-bin/device-management-utilities-internet.cgi endpoint of the MitraStar GPT-2741GNAC-N2-SV router, causing the system to concatenate parameters and execute arbitrary operating system commands. The vulnerability allows complete control over the router’s operating system, enabling the attacker to modify configurations, exfiltrate data, or pivot to other network assets.
Affected Systems
The affected device is a MitraStar GPT-2741GNAC-N2-SV router running firmware BR_g8.10_1.11(WVK.0)b46. No other vendor or product versions are listed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. However, because it permits remote command execution once authenticated, the potential impact remains severe. The likely attack vector is an authenticated user within the router’s local network, possibly leveraging existing credentials or a breached management account. Given the lack of an immediately available public patch, the risk remains elevated until a mitigated firmware version or workaround is deployed.
OpenCVE Enrichment