CVE-2019-6275: Command Injection
Published Mar 19, 2019
·Updated
Command injection vulnerability in firmwarecgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Affected Software
4 affected components
All of the following
gl-inet Gl-ar300m-lite Firmware=2.27
gl-inet Gl-ar300m-lite
gl-inet Gl-ar300m-lite Firmware=2.27
gl-inet Gl-ar300m-lite
Event History
Mar 19, 2019
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-6275?
CVE-2019-6275 is a command injection vulnerability in GL.iNet GL-AR300M-Lite devices with firmware 2.27.
2
How severe is CVE-2019-6275?
CVE-2019-6275 has a severity rating of 8.8 (high).
3
How can attackers exploit CVE-2019-6275?
Attackers can exploit CVE-2019-6275 by executing arbitrary code remotely.
4
Which software versions are affected by CVE-2019-6275?
GL.iNet GL-AR300M-Lite devices with firmware 2.27 are affected by CVE-2019-6275.
5
How can I fix CVE-2019-6275?
To fix CVE-2019-6275, users should update to a patched version of the firmware.