CVE-2025-25684: Path Traversal
A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the device's file system via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25684?
CVE-2025-25684 is classified as a high-severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2025-25684?
To fix CVE-2025-25684, update GL-iNet Beryl AX to a patched version that includes proper validation for file download requests.
What systems are affected by CVE-2025-25684?
CVE-2025-25684 affects GL-iNet Beryl AX GL-MT3000 version 4.7.0 and potentially earlier versions.
What type of attack is associated with CVE-2025-25684?
CVE-2025-25684 is related to a path traversal attack that allows attackers to download arbitrary files from the device.
What should I do if I can't immediately patch CVE-2025-25684?
If an immediate patch for CVE-2025-25684 is not available, consider restricting access to the device and monitoring for unusual activity.