Vulnerability Description
A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-E750 Firmware | < 3.216 |
| Gl-Inet | Gl-E750 | - |
Related Weaknesses (CWE)
References
- https://justinapplegate.me/2023/glinet-CVE-2023-24261/ExploitThird Party Advisory
- https://justinapplegate.me/2023/glinet-CVE-2023-24261/ExploitThird Party Advisory
FAQ
What is CVE-2023-24261?
CVE-2023-24261 is a vulnerability with a CVSS score of 7.2 (HIGH). A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.
How severe is CVE-2023-24261?
CVE-2023-24261 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-24261?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-E750 Firmware, Gl-Inet Gl-E750.