CVE-2023-29778: OS Command Injection
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate OS Command Injection exposure by restricting access to the vulnerable endpoint/path (/usr/lib/oui-httpd/rpc/logread) to trusted clients only (e.g., via firewall/ACL), until the device firmware is patched.
Event History
Frequently Asked Questions
What is the vulnerability ID of GL.iNET MT3000?
The vulnerability ID of GL.iNET MT3000 is CVE-2023-29778.
What is the severity level of CVE-2023-29778?
The severity level of CVE-2023-29778 is critical with a CVSS score of 9.8.
How does the vulnerability in GL.iNET MT3000 occur?
The vulnerability in GL.iNET MT3000 occurs due to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
Which software versions of GL.iNET MT3000 are affected?
The software version affected by the vulnerability is 4.1.0 Release 2 of GL.iNET MT3000.
Is GL.iNET MT3000 vulnerable to the command injection?
Yes, GL.iNET MT3000 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.