CVE-2024-27356: Infoleak
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27356?
The severity of CVE-2024-27356 is considered high due to the potential for attackers to access sensitive user information.
How do I fix CVE-2024-27356?
To mitigate CVE-2024-27356, update your GL-iNet device firmware to the latest version as recommended by the manufacturer.
What devices are affected by CVE-2024-27356?
CVE-2024-27356 affects various GL-iNet devices including MT6000, XE3000, X3000, MT3000, MT2500, AXT1800, AX1800, A1300, and S200, among others.
What types of data can attackers access through CVE-2024-27356?
Attackers exploiting CVE-2024-27356 may download files such as logs, which can contain critical user information.
Are there any known exploits for CVE-2024-27356?
Yes, there are known exploits for CVE-2024-27356 that demonstrate the vulnerability in GL-iNet devices.