CVE-2024-45262

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.
Configurations

No configuration.

History

No history.

Information

Published : 2024-10-24 21:15

Updated : 2024-10-28 20:35


NVD link : CVE-2024-45262

Mitre link : CVE-2024-45262

CVE.ORG link : CVE-2024-45262


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')