Description
An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a command injection flaw that allows an authenticated user to cause the device to execute arbitrary system commands through the /cgi-bin/device-management-utilities-internet.cgi CGI script. An attacker who can first authenticate to the device can then supply specially crafted input that is passed unchecked to an operating‑system command line, giving full control over the device and all data it manages.

Affected Systems

This issue appears in MitraStar GPT-2742GX4X5v6-SV GL_g2.5 100XNT0b23_3 firmware. Devices exposing the device-management-utilities-internet.cgi interface, which is typically accessed through the device's web management portal, are affected. No specific version range is listed, so all deployments using this component are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 reflects a high impact, and the EPSS score of < 1% indicates a very low likelihood of exploitation, yet the ability to execute code on an authenticated target still makes the risk significant. The vulnerability is not listed in CISA’s KEV catalog, but the severity suggests that the problem is actionable. Attacking the CGI via the standard web interface appears to be the most straightforward exploitation path; an attacker would need valid credentials but then could run arbitrary commands without additional constraints.

Generated by OpenCVE AI on September 20, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the command injection flaw in the device‑management‑utilities‑internet.cgi component.
  • If the CGI interface is not required for business operations, disable or remove the /cgi-bin/device-management-utilities‑internet.cgi script from the device's web server.
  • Enforce strong authentication controls and limit access to the management interface, ensuring only trusted administrators can log in, and consider implementing two‑factor authentication if supported.

Generated by OpenCVE AI on September 20, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via CGI Command Injection on MitraStar Device

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Command Injection in MitraStar Device Management CGI Allows Remote Code Execution

Wed, 16 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Command Injection in MitraStar Device Management CGI Allows Remote Code Execution

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T19:08:07.957Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52484

cve-icon Vulnrichment

Updated: 2026-09-15T19:07:40.114Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:22.010

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-52484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')