vendor:
GL-iNet MT6000
by:
Bandar Alharbi
6.1
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: GL-iNet MT6000
Affected Version From: 4.5.2005
Affected Version To: 4.5.2005
Patch Exists: NO
Related CWE: CVE-2024-27356
CPE: h:gl-inet:gl-inet_mt6000:4.5.5
Platforms Tested:
2024
GL-iNet MT6000 4.5.5 – Arbitrary File Download
The GL-iNet MT6000 4.5.5 device is vulnerable to an arbitrary file download exploit. By exploiting this vulnerability, an attacker can download sensitive information such as credentials and registered Device ID. This vulnerability has been assigned CVE-2024-27356.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches provided by the vendor. Additionally, restrict network access to the GL-iNet MT6000 device to trusted entities only.