Impact
The vulnerability is a command injection flaw that allows an authenticated user to cause the device to execute arbitrary system commands through the /cgi-bin/device-management-utilities-internet.cgi CGI script. An attacker who can first authenticate to the device can then supply specially crafted input that is passed unchecked to an operating‑system command line, giving full control over the device and all data it manages.
Affected Systems
This issue appears in MitraStar GPT-2742GX4X5v6-SV GL_g2.5 100XNT0b23_3 firmware. Devices exposing the device-management-utilities-internet.cgi interface, which is typically accessed through the device's web management portal, are affected. No specific version range is listed, so all deployments using this component are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact, and the EPSS score of < 1% indicates a very low likelihood of exploitation, yet the ability to execute code on an authenticated target still makes the risk significant. The vulnerability is not listed in CISA’s KEV catalog, but the severity suggests that the problem is actionable. Attacking the CGI via the standard web interface appears to be the most straightforward exploitation path; an attacker would need valid credentials but then could run arbitrary commands without additional constraints.
OpenCVE Enrichment