CVE-2025-50753

Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" is supposed to be used from restricted shell to show files and directories. By providing " /bin/sh" (quotes included) to the argument of this command will drop a root shell.
Configurations

No configuration.

History

27 Aug 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Los dispositivos Mitrastar GPT-2741GNAC-N2 tienen acceso a través de SSH a un shell predeterminado restringido. El comando "deviceinfo show file" debe usarse desde un shell restringido para mostrar archivos y directorios. Al añadir "/bin/sh" (entre comillas) al argumento de este comando, se eliminará un shell root.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CWE CWE-250

26 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 14:15

Updated : 2025-08-29 16:22


NVD link : CVE-2025-50753

Mitre link : CVE-2025-50753

CVE.ORG link : CVE-2025-50753


JSON object : View

Products Affected

No product.

CWE
CWE-250

Execution with Unnecessary Privileges