CVE-2024-45261: High severity gl-inet GL-iNet Devices vulnerability
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45261?
The severity of CVE-2024-45261 is defined as critical due to the risk of unauthorized access to user accounts.
How do I fix CVE-2024-45261?
To fix CVE-2024-45261, update the affected GL-iNet devices to the latest firmware version that addresses the vulnerability.
Which devices are affected by CVE-2024-45261?
CVE-2024-45261 affects certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 running version 4.6.2.
What is the cause of the vulnerability CVE-2024-45261?
The cause of CVE-2024-45261 is that the SID generated for users is not tied to the specific user, allowing potential authentication bypass.
Can CVE-2024-45261 be exploited remotely?
Yes, CVE-2024-45261 can potentially be exploited remotely if an attacker has the means to generate or intercept the user SID.