CVE-2024-45263: Malicious File Upload
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45263?
CVE-2024-45263 is considered a high-severity vulnerability due to the potential for remote code execution and information leakage.
How can I mitigate CVE-2024-45263?
Mitigation for CVE-2024-45263 includes restricting access to the upload interface and applying firmware updates that address this issue.
Which devices are affected by CVE-2024-45263?
CVE-2024-45263 affects GL-iNet devices, specifically MT6000, MT3000, MT2500, AXT1800, and AX1800 models.
What types of attacks can CVE-2024-45263 enable?
CVE-2024-45263 could enable attackers to execute arbitrary files, leading to unauthorized access and complete control over the affected device.
Is there a known fix for CVE-2024-45263?
Yes, the vendor has released updated firmware to address the vulnerabilities associated with CVE-2024-45263, which should be installed immediately.