CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreSep 29, 2025 Oct 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the fi...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentia...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete co...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on t...Show more |