Description
The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request for the endpoint /cgi-bin/device-management-utilities-internet.cgi.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Apply Firmware Update
AI Analysis

Impact

Authenticated users can craft a POST request to the /cgi-bin/device-management-utilities-internet.cgi endpoint of the MitraStar GPT-2741GNAC-N2-SV router, causing the system to concatenate parameters and execute arbitrary operating system commands. The vulnerability allows complete control over the router’s operating system, enabling the attacker to modify configurations, exfiltrate data, or pivot to other network assets.

Affected Systems

The affected device is a MitraStar GPT-2741GNAC-N2-SV router running firmware BR_g8.10_1.11(WVK.0)b46. No other vendor or product versions are listed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1%, indicating a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. However, because it permits remote command execution once authenticated, the potential impact remains severe. The likely attack vector is an authenticated user within the router’s local network, possibly leveraging existing credentials or a breached management account. Given the lack of an immediately available public patch, the risk remains elevated until a mitigated firmware version or workaround is deployed.

Generated by OpenCVE AI on September 20, 2026 at 04:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the router firmware to a version that addresses the command execution flaw.
  • If a firmware update is not available, restrict or disable the /cgi-bin/device-management-utilities-internet.cgi endpoint or block it at the network perimeter.
  • Ensure only trusted users have administrative access and change default credentials to strong, unique passwords.
  • Consider network segmentation to isolate the router from critical internal assets.

Generated by OpenCVE AI on September 20, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authenticated OS Command Execution via Crafted POST Request on MitraStar GPT-2741GNAC-N2-SV Router

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request for the endpoint /cgi-bin/device-management-utilities-internet.cgi.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-19T02:12:10.054Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52483

cve-icon Vulnrichment

Updated: 2026-09-19T02:11:09.420Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:14.870

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-52483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')