CVE-2024-45259: Weak Encryption
Published Oct 24, 2024
·Updated
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.
Affected Software
43 affected components
gl-inet GL-iNet Devices
All of the following
gl-inet Mt3000 Firmware=4.6.2
gl-inet Gl-mt3000
All of the following
gl-inet Mt2500 Firmware>=4.6.2<4.6.4
gl-inet MT2500
All of the following
gl-inet Axt1800 Firmware>=4.6.2<4.6.4
gl-inet AXT1800
All of the following
gl-inet Ax1800 Firmware>=4.6.2<4.6.4
gl-inet AX1800
All of the following
gl-inet B3000 Firmware=4.5.18
gl-inet B3000
All of the following
gl-inet A1300 Firmware=4.5.17
gl-inet A1300
All of the following
gl-inet X300b Firmware=4.5.17
gl-inet X300B
All of the following
gl-inet X3000 Firmware=4.4.9
gl-inet X3000
All of the following
gl-inet Xe3000 Firmware=4.4.9
gl-inet XE3000
All of the following
gl-inet X750 Firmware=4.3.18
gl-inet X750
All of the following
gl-inet Sft1200 Firmware=4.3.18
gl-inet SFT1200
All of the following
gl-inet Mt1300 Firmware=4.3.18
gl-inet MT1300
All of the following
gl-inet E750 Firmware=4.3.17
gl-inet E750
All of the following
gl-inet Xe300 Firmware=4.3.17
gl-inet XE300
All of the following
gl-inet Ar750 Firmware=4.3.17
gl-inet AR750
All of the following
gl-inet Ar750s Firmware=4.3.17
gl-inet AR750S
All of the following
gl-inet Ar300m Firmware=4.3.17
gl-inet AR300M
All of the following
gl-inet Ar300m16 Firmware=4.3.17
gl-inet AR300M16
All of the following
gl-inet Mt300n-v2 Firmware=4.3.17
gl-inet MT300N-V2
All of the following
gl-inet B1300 Firmware=4.3.17
gl-inet B1300
All of the following
gl-inet Mt6000 Firmware=4.6.2
gl-inet MT6000
Event History
Oct 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45259?
The severity of CVE-2024-45259 is considered high due to its potential impact on file integrity.
2
How do I fix CVE-2024-45259?
To fix CVE-2024-45259, update your GL-iNet device firmware to the latest version provided by the manufacturer.
3
What devices are affected by CVE-2024-45259?
CVE-2024-45259 affects GL-iNet devices including MT6000, MT3000, MT2500, AXT1800, and AX1800.
4
What types of files can be deleted due to CVE-2024-45259?
Any file on the affected GL-iNet devices can be deleted by exploiting CVE-2024-45259.
5
How does CVE-2024-45259 exploit the download interface?
CVE-2024-45259 exploits the download interface by intercepting HTTP requests and altering the filename property.