CVE-2019-6272: Command Injection
Published Mar 19, 2019
·Updated
Command injection vulnerability in logincgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Affected Software
4 affected components
All of the following
gl-inet Gl-ar300m-lite Firmware=2.27
gl-inet Gl-ar300m-lite
gl-inet Gl-ar300m-lite Firmware=2.27
gl-inet Gl-ar300m-lite
Event History
Mar 19, 2019
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6272?
The severity of CVE-2019-6272 is high (8.8).
2
What is the affected software for CVE-2019-6272?
The affected software for CVE-2019-6272 is GL.iNet GL-AR300M-Lite devices with firmware 2.27.
3
How does CVE-2019-6272 affect GL.iNet GL-AR300M-Lite devices?
CVE-2019-6272 allows remote attackers to execute arbitrary code on GL.iNet GL-AR300M-Lite devices with firmware 2.27.
4
Is GL.iNet GL-AR300M-Lite vulnerable to CVE-2019-6272?
No, GL.iNet GL-AR300M-Lite devices are not vulnerable to CVE-2019-6272.
5
How can the command injection vulnerability in login_cgi be exploited for CVE-2019-6272?
The command injection vulnerability in login_cgi can be exploited by remote attackers to execute arbitrary code.