CVE-2025-67089: Command Injection
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the plugins.installpackage RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67089?
The severity of CVE-2025-67089 is considered high due to the potential for unauthorized remote command execution.
How do I fix CVE-2025-67089?
To fix CVE-2025-67089, update the GL-iNet GL-AXT1800 router firmware to the latest version provided by the vendor.
Who is affected by CVE-2025-67089?
CVE-2025-67089 affects users of the GL-iNet GL-AXT1800 router running firmware version 4.6.8.
What type of vulnerability is CVE-2025-67089?
CVE-2025-67089 is a command injection vulnerability that allows authenticated attackers to execute arbitrary commands.
What methods can be used to exploit CVE-2025-67089?
CVE-2025-67089 can be exploited through the `plugins.install_package` RPC method by providing unsanitized input.