CVE-2024-45261
HIGHDescription
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.
Is your site exposed to CVE-2024-45261?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gl-inet | mt2500_firmware |
| gl-inet | mt2500 |
| gl-inet | axt1800_firmware |
| gl-inet | axt1800 |
| gl-inet | ax1800_firmware |
| gl-inet | ax1800 |
| gl-inet | b3000_firmware |
| gl-inet | b3000 |
| gl-inet | a1300_firmware |
| gl-inet | a1300 |
| gl-inet | x300b_firmware |
| gl-inet | x300b |
| gl-inet | x3000_firmware |
| gl-inet | x3000 |
| gl-inet | xe3000_firmware |
| gl-inet | xe3000 |
| gl-inet | x750_firmware |
| gl-inet | x750 |
| gl-inet | sft1200_firmware |
| gl-inet | sft1200 |
| gl-inet | mt1300_firmware |
| gl-inet | mt1300 |
| gl-inet | e750_firmware |
| gl-inet | e750 |
| gl-inet | xe300_firmware |
| gl-inet | xe300 |
| gl-inet | ar750_firmware |
| gl-inet | ar750 |
| gl-inet | ar750s_firmware |
| gl-inet | ar750s |
| gl-inet | ar300m_firmware |
| gl-inet | ar300m |
| gl-inet | mt300n-v2_firmware |
| gl-inet | mt300n-v2 |
| gl-inet | mt3000_firmware |
| gl-inet | gl-mt3000 |
| gl-inet | ar300m16_firmware |
| gl-inet | ar300m16 |
| gl-inet | mt6000_firmware |
| gl-inet | mt6000 |
| gl-inet | b1300_firmware |
| gl-inet | b1300 |
References
Frequently Asked Questions
What is CVE-2024-45261? +
How severe is CVE-2024-45261? +
What products are affected by CVE-2024-45261? +
How do I check if I'm vulnerable to CVE-2024-45261? +
Related Vulnerabilities
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik …
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version …
A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. …
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization …