Vulnerability Description
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-Axt1800 Firmware | 4.2.0 |
| Gl-Inet | Gl-Axt1800 | - |
Related Weaknesses (CWE)
References
- https://aleksazatezalo.medium.com/critical-command-injection-vulnerability-in-glExploitThird Party AdvisoryPress/Media Coverage
- https://www.gl-inet.com/security-updates/Vendor Advisory
FAQ
What is CVE-2025-67089?
CVE-2025-67089 is a vulnerability with a CVSS score of 8.1 (HIGH). A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize us...
How severe is CVE-2025-67089?
CVE-2025-67089 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67089?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Axt1800 Firmware, Gl-Inet Gl-Axt1800.