An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-10-24 20:15
Updated : 2024-10-28 20:35
NVD link : CVE-2024-45259
Mitre link : CVE-2024-45259
CVE.ORG link : CVE-2024-45259
JSON object : View
Products Affected
No product.
CWE
CWE-326
Inadequate Encryption Strength