CVE-2025-25685

An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.
Configurations

No configuration.

History

21 Mar 2025, 14:15

Type Values Removed Values Added
CWE CWE-22
References () https://medium.com/@tfortinsec/multiple-path-traversal-vulnerabilities-in-the-beryl-ax-gl-mt300-router-e7f856d14af9 - () https://medium.com/@tfortinsec/multiple-path-traversal-vulnerabilities-in-the-beryl-ax-gl-mt300-router-e7f856d14af9 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Se descubrió un problema en GL-INet Beryl AX GL-MT3000 v4.7.0. Los atacantes pueden descargar archivos arbitrarios del sistema de archivos del dispositivo añadiendo enlaces simbólicos en una unidad externa utilizada como recurso compartido de Samba.

17 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-17 17:15

Updated : 2025-03-21 14:15


NVD link : CVE-2025-25685

Mitre link : CVE-2025-25685

CVE.ORG link : CVE-2025-25685


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')