CVE-2024-45261
HIGHDescription
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.
Is your site exposed to CVE-2024-45261?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gl-inet | mt2500_firmware |
| gl-inet | mt2500 |
| gl-inet | axt1800_firmware |
| gl-inet | axt1800 |
| gl-inet | ax1800_firmware |
| gl-inet | ax1800 |
| gl-inet | b3000_firmware |
| gl-inet | b3000 |
| gl-inet | a1300_firmware |
| gl-inet | a1300 |
| gl-inet | x300b_firmware |
| gl-inet | x300b |
| gl-inet | x3000_firmware |
| gl-inet | x3000 |
| gl-inet | xe3000_firmware |
| gl-inet | xe3000 |
| gl-inet | x750_firmware |
| gl-inet | x750 |
| gl-inet | sft1200_firmware |
| gl-inet | sft1200 |
| gl-inet | mt1300_firmware |
| gl-inet | mt1300 |
| gl-inet | e750_firmware |
| gl-inet | e750 |
| gl-inet | xe300_firmware |
| gl-inet | xe300 |
| gl-inet | ar750_firmware |
| gl-inet | ar750 |
| gl-inet | ar750s_firmware |
| gl-inet | ar750s |
| gl-inet | ar300m_firmware |
| gl-inet | ar300m |
| gl-inet | mt300n-v2_firmware |
| gl-inet | mt300n-v2 |
| gl-inet | mt3000_firmware |
| gl-inet | gl-mt3000 |
| gl-inet | ar300m16_firmware |
| gl-inet | ar300m16 |
| gl-inet | mt6000_firmware |
| gl-inet | mt6000 |
| gl-inet | b1300_firmware |
| gl-inet | b1300 |
References
Frequently Asked Questions
What is CVE-2024-45261? +
How severe is CVE-2024-45261? +
What products are affected by CVE-2024-45261? +
How do I check if I'm vulnerable to CVE-2024-45261? +
Related Vulnerabilities
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version …
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization …
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 …
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the …